Repository navigation
ci: move GitHub Actions off the deprecated Node 20 runtime (ODIAA-2337) - #29
Merged
Merged
Conversation
Bump actions/checkout v4 -> v7, actions/setup-node v4 -> v7 and softprops/action-gh-release v2 -> v3 in test.yml, release.yml and sign-xpi.yml. All three now run on node24. setup-node v7 no longer exports a dummy NODE_AUTH_TOKEN, which matches our OIDC trusted-publishing flow (no token is set). The npm-publish job also sets package-manager-cache: false, as setup-node's trusted-publisher docs recommend. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The v1.2.1 release run warned that three actions still run on the deprecated Node 20 action runtime. This PR bumps each one to its latest node24 major:
Changed files:
test.yml(CI),release.ymlandsign-xpi.yml. The repo has noci.yml;test.ymlis the CI workflow.OIDC / npm publish
NODE_AUTH_TOKEN(Remove dummy NODE_AUTH_TOKEN export actions/setup-node#1558). Ournpm-publishjob never sets a token, so npm ≥ 11.5.1 does the OIDC exchange itself. This matches the trusted-publisher example in setup-node's docs, which keepsregistry-urland sets no token.package-manager-cache: false, as those docs recommend, so no restored cache runs next to the OIDC token.pull_request_target/workflow_run. We use neither trigger.Not changed
The Node versions we test and build on (
node-version20/22) stay the same. Only the runtime the actions themselves use changes.Test plan
testsworkflow is green on Node 20 and 22 (this PR)releasejob creates the GitHub Release, andnpm-publishpublishes with provenance through OIDC🤖 Generated with Claude Code