diff --git a/.github/workflows/ai-changeset.yml b/.github/workflows/ai-changeset.yml index e9517255d..781a2ff53 100644 --- a/.github/workflows/ai-changeset.yml +++ b/.github/workflows/ai-changeset.yml @@ -37,12 +37,12 @@ jobs: id: app-token if: ${{ vars.CHANGELOG_APP_ID != '' }} continue-on-error: true - uses: actions/create-github-app-token@v1 + uses: actions/create-github-app-token@v3 with: app-id: ${{ vars.CHANGELOG_APP_ID }} private-key: ${{ secrets.CHANGELOG_APP_PRIVATE_KEY }} - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: ref: ${{ github.event.pull_request.head.ref }} fetch-depth: 0 @@ -51,10 +51,10 @@ jobs: - name: Ensure base ref is present run: git fetch --no-tags origin ${{ github.event.pull_request.base.ref }} - - uses: pnpm/action-setup@v4 + - uses: pnpm/action-setup@v6 with: version: '10.30.3' - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version: '23' cache: 'pnpm' @@ -130,7 +130,7 @@ jobs: # For fork PRs (cannot push) surface the suggestion as a comment instead. - name: Suggest changeset on fork PRs if: ${{ steps.gate.outputs.covered != 'true' && github.event.pull_request.head.repo.full_name != github.repository }} - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const fs = require('node:fs') diff --git a/.github/workflows/changelog-check.yml b/.github/workflows/changelog-check.yml index 0ee88b19d..25b25f8c8 100644 --- a/.github/workflows/changelog-check.yml +++ b/.github/workflows/changelog-check.yml @@ -22,7 +22,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Require a changelog fragment (or skip-changelog label) - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const { owner, repo } = context.repo diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 20b97aa28..4aa516f18 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -47,7 +47,7 @@ jobs: # the commit that introduced it. A shallow clone has no such commit, so # draft ages would be unreadable. Keep enough history for an honest report; # staleness itself is informational and never a merge gate. - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - uses: ./.github/actions/setup @@ -187,10 +187,10 @@ jobs: # only move the silent pass one level down. if: github.event_name != 'push' steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version: '23' @@ -216,7 +216,7 @@ jobs: typecheck: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup - name: Build & Type check @@ -254,7 +254,7 @@ jobs: matrix: shard: [1/3, 2/3, 3/3] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - uses: ./.github/actions/setup @@ -304,7 +304,7 @@ jobs: # in this job reads PR context, so the unknown-event path is sound as-is. if: github.event_name != 'push' steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup - name: Build packages @@ -317,7 +317,7 @@ jobs: # libraries present. (Exploration 0193.) - name: Cache Playwright browsers id: playwright-cache - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: ~/.cache/ms-playwright key: playwright-${{ runner.os }}-1.58.1-chromium-webkit @@ -358,7 +358,7 @@ jobs: # lives in the visual-capture workflow; this just keeps debug evidence. - name: Upload editor UX screenshots if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: editor-ux-screenshots # Playwright runs with cwd=tests/e2e, so screenshots land there; the @@ -389,7 +389,7 @@ jobs: # PR context either (fetch-depth: 0 is for history, not for a base ref). if: github.event_name != 'push' steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - uses: ./.github/actions/setup @@ -407,7 +407,7 @@ jobs: - name: Cache Playwright browser id: playwright-cache - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: ~/.cache/ms-playwright key: playwright-${{ runner.os }}-1.58.1-chromium @@ -447,7 +447,7 @@ jobs: - name: Upload Electron e2e artifacts if: failure() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: electron-e2e-artifacts path: | @@ -464,9 +464,9 @@ jobs: conformance-rust: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Cache cargo - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: | ~/.cargo/registry diff --git a/.github/workflows/cloud-metrics.yml b/.github/workflows/cloud-metrics.yml index dcfce11c1..d36315c81 100644 --- a/.github/workflows/cloud-metrics.yml +++ b/.github/workflows/cloud-metrics.yml @@ -27,8 +27,8 @@ jobs: if: ${{ vars.CLOUD_METRICS_ENABLED == 'true' }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-node@v7 with: node-version: 22 @@ -43,7 +43,7 @@ jobs: rm -f company-metrics.json - name: Open a PR if the snapshot changed - uses: peter-evans/create-pull-request@v6 + uses: peter-evans/create-pull-request@v8 with: commit-message: 'chore(open): refresh run-in-public metrics snapshot' title: 'chore(open): weekly run-in-public metrics refresh' diff --git a/.github/workflows/dco.yml b/.github/workflows/dco.yml index 303aaab3b..514ba7b5b 100644 --- a/.github/workflows/dco.yml +++ b/.github/workflows/dco.yml @@ -17,7 +17,7 @@ jobs: name: Signed-off-by on every commit runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 ref: ${{ github.event.pull_request.head.sha }} diff --git a/.github/workflows/dependency-audit.yml b/.github/workflows/dependency-audit.yml index 9cdcb9485..7da479ba3 100644 --- a/.github/workflows/dependency-audit.yml +++ b/.github/workflows/dependency-audit.yml @@ -37,7 +37,7 @@ jobs: name: Audit runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup - name: Negative control diff --git a/.github/workflows/deploy-branch-preview.yml b/.github/workflows/deploy-branch-preview.yml index abd577665..d9055186f 100644 --- a/.github/workflows/deploy-branch-preview.yml +++ b/.github/workflows/deploy-branch-preview.yml @@ -21,7 +21,7 @@ jobs: if: github.ref_name != 'main' && github.ref_name != 'gh-pages' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup diff --git a/.github/workflows/deploy-cloud.yml b/.github/workflows/deploy-cloud.yml index 429daf56f..d61960c63 100644 --- a/.github/workflows/deploy-cloud.yml +++ b/.github/workflows/deploy-cloud.yml @@ -65,15 +65,15 @@ jobs: BASE_URL: https://cloud-staging.xnet.fyi HUB_IMAGE_TAG: '1.0.0' # plain image tag each provisioned hub is pinned to (repo:TAG; '@' is not a valid Docker tag) steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - id: auth - uses: google-github-actions/auth@v2 + uses: google-github-actions/auth@v3 with: workload_identity_provider: ${{ secrets.WIF_PROVIDER }} service_account: ${{ secrets.DEPLOYER_SA }} - - uses: google-github-actions/setup-gcloud@v2 + - uses: google-github-actions/setup-gcloud@v3 - name: Build + push control-plane image run: | @@ -167,15 +167,15 @@ jobs: BASE_URL: https://cloud.xnet.fyi HUB_IMAGE_TAG: '1.0.0' steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - id: auth - uses: google-github-actions/auth@v2 + uses: google-github-actions/auth@v3 with: workload_identity_provider: ${{ secrets.PROD_WIF_PROVIDER }} service_account: ${{ secrets.PROD_DEPLOYER_SA }} - - uses: google-github-actions/setup-gcloud@v2 + - uses: google-github-actions/setup-gcloud@v3 # A tenant whose payment lapses is emailed before their hub degrades and # again before its cloud replica is deleted. With no mail transport the diff --git a/.github/workflows/deploy-pr-preview.yml b/.github/workflows/deploy-pr-preview.yml index 34e34e298..6ce348c6d 100644 --- a/.github/workflows/deploy-pr-preview.yml +++ b/.github/workflows/deploy-pr-preview.yml @@ -24,7 +24,7 @@ jobs: name: pr-${{ github.event.pull_request.number }} url: https://xnet.fyi/pr/${{ github.event.pull_request.number }}/app/ steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: ref: ${{ github.event.pull_request.head.sha }} @@ -72,7 +72,7 @@ jobs: commit-message: 'deploy(preview): publish PR #${{ github.event.pull_request.number }} demos preview' - name: Comment preview link - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const body = [ diff --git a/.github/workflows/deploy-site.yml b/.github/workflows/deploy-site.yml index 2403d5c93..36fc9f64c 100644 --- a/.github/workflows/deploy-site.yml +++ b/.github/workflows/deploy-site.yml @@ -26,7 +26,7 @@ jobs: deploy: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: # Full history so resolve-prs can find each fragment's merge commit. fetch-depth: 0 @@ -56,7 +56,7 @@ jobs: VITE_BASE_PATH: '/play/' - name: Cache Astro build - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: site/.astro key: astro-${{ hashFiles('site/pnpm-lock.yaml', 'site/src/**', 'site/astro.config.mjs') }} diff --git a/.github/workflows/electron-release.yml b/.github/workflows/electron-release.yml index 8f0e18516..5a6c0087b 100644 --- a/.github/workflows/electron-release.yml +++ b/.github/workflows/electron-release.yml @@ -50,7 +50,7 @@ jobs: should_release: ${{ steps.check.outputs.should_release }} should_build: ${{ steps.check.outputs.should_build }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Get version from package.json id: version @@ -128,14 +128,14 @@ jobs: if: needs.version.outputs.should_build == 'true' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup - name: Build packages run: pnpm build - name: Upload JS build artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: js-build path: | @@ -152,13 +152,13 @@ jobs: matrix: arch: [x64, arm64] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup with: electron-cache: 'true' - name: Download JS build artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: js-build path: . @@ -285,7 +285,7 @@ jobs: xcrun stapler staple "$DMG_FILE" - name: Upload artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: macos-${{ matrix.arch }} path: | @@ -303,13 +303,13 @@ jobs: # sharp). better-sqlite3 is unaffected — it ships an Electron prebuild. runs-on: windows-2022 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup with: electron-cache: 'true' - name: Download JS build artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: js-build path: . @@ -334,7 +334,7 @@ jobs: pnpm electron-builder --win --x64 --publish never - name: Upload artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: windows-x64 path: | @@ -349,13 +349,13 @@ jobs: matrix: arch: [x64, arm64] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup with: electron-cache: 'true' - name: Download JS build artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: js-build path: . @@ -407,7 +407,7 @@ jobs: exit $rc - name: Upload artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: linux-${{ matrix.arch }} path: | @@ -423,10 +423,10 @@ jobs: if: needs.version.outputs.should_release == 'true' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Download all artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: path: artifacts diff --git a/.github/workflows/fallow.yml b/.github/workflows/fallow.yml index 4cb111ba3..e064ebcb5 100644 --- a/.github/workflows/fallow.yml +++ b/.github/workflows/fallow.yml @@ -36,7 +36,7 @@ jobs: env: HUSKY: '0' steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 @@ -88,7 +88,7 @@ jobs: env: HUSKY: '0' steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 @@ -162,7 +162,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 diff --git a/.github/workflows/gh-pages-maintenance.yml b/.github/workflows/gh-pages-maintenance.yml index 011e2fa94..868355d34 100644 --- a/.github/workflows/gh-pages-maintenance.yml +++ b/.github/workflows/gh-pages-maintenance.yml @@ -27,7 +27,7 @@ jobs: if: github.repository_owner == 'crs48' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Find orphaned previews id: sweep @@ -108,7 +108,7 @@ jobs: # merged PR never shows broken images. Comment-only; safe to no-op. - name: Tombstone expired visuals comments if: steps.sweep.outputs.tombstone != '' - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const marker = '' diff --git a/.github/workflows/hub-image.yml b/.github/workflows/hub-image.yml index e9de732f7..c19f0989b 100644 --- a/.github/workflows/hub-image.yml +++ b/.github/workflows/hub-image.yml @@ -55,13 +55,13 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 25 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@v4 - name: Build hub image (same build Railway runs) - uses: docker/build-push-action@v5 + uses: docker/build-push-action@v7 with: context: . file: packages/hub/Dockerfile diff --git a/.github/workflows/hub-release.yml b/.github/workflows/hub-release.yml index a2a0e19e6..fdb80db91 100644 --- a/.github/workflows/hub-release.yml +++ b/.github/workflows/hub-release.yml @@ -19,16 +19,16 @@ jobs: version: ${{ steps.meta.outputs.version }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up QEMU - uses: docker/setup-qemu-action@v3 + uses: docker/setup-qemu-action@v4 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 + uses: docker/setup-buildx-action@v4 - name: Log in to Container Registry - uses: docker/login-action@v3 + uses: docker/login-action@v4 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} @@ -36,7 +36,7 @@ jobs: - name: Extract metadata id: meta - uses: docker/metadata-action@v5 + uses: docker/metadata-action@v6 with: images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} tags: | @@ -45,7 +45,7 @@ jobs: type=raw,value=latest - name: Build and push - uses: docker/build-push-action@v5 + uses: docker/build-push-action@v7 with: context: . file: packages/hub/Dockerfile @@ -81,6 +81,6 @@ jobs: output: 'trivy-results.sarif' - name: Upload Trivy scan results - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: 'trivy-results.sarif' diff --git a/.github/workflows/native-helpers.yml b/.github/workflows/native-helpers.yml index 406f18abb..f0c01cd86 100644 --- a/.github/workflows/native-helpers.yml +++ b/.github/workflows/native-helpers.yml @@ -21,7 +21,7 @@ jobs: runs-on: macos-14 timeout-minutes: 15 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Build xnet-audiotee (release) working-directory: apps/electron/native/audiotee @@ -31,7 +31,7 @@ jobs: runs-on: macos-14 timeout-minutes: 15 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Build xnet-screencap (release) working-directory: apps/electron/native/screencap diff --git a/.github/workflows/npm-release.yml b/.github/workflows/npm-release.yml index d076be1ef..0cd53bc52 100644 --- a/.github/workflows/npm-release.yml +++ b/.github/workflows/npm-release.yml @@ -23,7 +23,7 @@ jobs: release: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 @@ -32,7 +32,7 @@ jobs: node-version: '24' - name: Setup npm registry auth context - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: '24' registry-url: 'https://registry.npmjs.org' @@ -47,7 +47,7 @@ jobs: - name: Create release PR or publish id: changesets - uses: changesets/action@v1 + uses: changesets/action@v2 with: github-token: ${{ secrets.RELEASE_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} commitMode: github-api diff --git a/.github/workflows/plugins-registry.yml b/.github/workflows/plugins-registry.yml index a5586ebf1..49505d41b 100644 --- a/.github/workflows/plugins-registry.yml +++ b/.github/workflows/plugins-registry.yml @@ -34,8 +34,8 @@ jobs: if: github.event_name == 'pull_request' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-node@v7 with: node-version: '24' - name: Validate submission sources @@ -48,8 +48,8 @@ jobs: contents: write pull-requests: write steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-node@v7 with: node-version: '24' @@ -64,7 +64,7 @@ jobs: # release PR. Same caveat too: GITHUB_TOKEN events don't trigger CI on # the PR, so it needs an admin-merge (see 0265's release-PR gotcha). - name: Open/refresh registry data PR - uses: peter-evans/create-pull-request@v7 + uses: peter-evans/create-pull-request@v8 with: branch: plugins-registry/data add-paths: | diff --git a/.github/workflows/remove-branch-preview.yml b/.github/workflows/remove-branch-preview.yml index 2d28c5f2b..384e6e9e2 100644 --- a/.github/workflows/remove-branch-preview.yml +++ b/.github/workflows/remove-branch-preview.yml @@ -17,7 +17,7 @@ jobs: if: github.event.ref_type == 'branch' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Compute branch slug id: slug diff --git a/.github/workflows/remove-pr-preview.yml b/.github/workflows/remove-pr-preview.yml index 3ce666324..07cff50e4 100644 --- a/.github/workflows/remove-pr-preview.yml +++ b/.github/workflows/remove-pr-preview.yml @@ -20,7 +20,7 @@ jobs: if: github.event.pull_request.head.repo.full_name == github.repository runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Remove preview from gh-pages uses: ./.github/actions/publish-gh-pages @@ -29,7 +29,7 @@ jobs: commit-message: 'deploy(preview): remove PR #${{ github.event.pull_request.number }} preview' - name: Deactivate pr environment deployments - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const environment = `pr-${context.payload.pull_request.number}` @@ -52,7 +52,7 @@ jobs: core.info(`Marked ${deployments.length} deployment(s) of ${environment} inactive.`) - name: Comment preview removal - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const body = [ diff --git a/.github/workflows/soak.yml b/.github/workflows/soak.yml index 825e069cb..036b52c61 100644 --- a/.github/workflows/soak.yml +++ b/.github/workflows/soak.yml @@ -49,7 +49,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 60 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup - name: Reliability suite at soak depth @@ -71,7 +71,7 @@ jobs: - name: Cache Playwright browsers id: playwright-cache - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: ~/.cache/ms-playwright key: playwright-${{ runner.os }}-1.58.1-chromium @@ -124,7 +124,7 @@ jobs: - name: Upload artifacts on failure if: failure() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: soak-artifacts path: | diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index 8e0cec4e1..56bd3d145 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -25,7 +25,7 @@ jobs: stale: runs-on: ubuntu-latest steps: - - uses: actions/stale@v9 + - uses: actions/stale@v11 with: days-before-stale: 14 days-before-close: 21 diff --git a/.github/workflows/stamp-pr-number.yml b/.github/workflows/stamp-pr-number.yml index 792b18341..bff9c8cb5 100644 --- a/.github/workflows/stamp-pr-number.yml +++ b/.github/workflows/stamp-pr-number.yml @@ -48,12 +48,12 @@ jobs: id: app-token if: ${{ vars.CHANGELOG_APP_ID != '' }} continue-on-error: true - uses: actions/create-github-app-token@v1 + uses: actions/create-github-app-token@v3 with: app-id: ${{ vars.CHANGELOG_APP_ID }} private-key: ${{ secrets.CHANGELOG_APP_PRIVATE_KEY }} - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: ref: main fetch-depth: 0 @@ -64,7 +64,7 @@ jobs: token: ${{ steps.app-token.outputs.token || secrets.CHANGELOG_BOT_TOKEN || github.token }} - name: Stamp PR number + contributors into this PR's changelog fragment(s) - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const fs = require('node:fs') diff --git a/.github/workflows/syndicate.yml b/.github/workflows/syndicate.yml index 1eb248f38..5990291ee 100644 --- a/.github/workflows/syndicate.yml +++ b/.github/workflows/syndicate.yml @@ -55,12 +55,12 @@ jobs: id: app-token if: ${{ vars.CHANGELOG_APP_ID != '' }} continue-on-error: true - uses: actions/create-github-app-token@v1 + uses: actions/create-github-app-token@v3 with: app-id: ${{ vars.CHANGELOG_APP_ID }} private-key: ${{ secrets.CHANGELOG_APP_PRIVATE_KEY }} - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: ref: main token: ${{ steps.app-token.outputs.token || secrets.CHANGELOG_BOT_TOKEN || github.token }} @@ -69,7 +69,7 @@ jobs: # nobody "hardens" it to false and silently breaks the push. persist-credentials: true - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version: 22 diff --git a/.github/workflows/undeploy-site.yml b/.github/workflows/undeploy-site.yml index b8d7f917d..1452f7142 100644 --- a/.github/workflows/undeploy-site.yml +++ b/.github/workflows/undeploy-site.yml @@ -14,7 +14,7 @@ jobs: undeploy: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Prepare offline placeholder run: | diff --git a/.github/workflows/visual-capture.yml b/.github/workflows/visual-capture.yml index c1feac674..da4b861e0 100644 --- a/.github/workflows/visual-capture.yml +++ b/.github/workflows/visual-capture.yml @@ -72,7 +72,7 @@ jobs: # job's shim-conformance check instead (exploration 0283). continue-on-error: true steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 ref: ${{ github.event.pull_request.head.sha }} @@ -93,7 +93,7 @@ jobs: # on a hit we still run install-deps (apt only). (Exploration 0193.) - name: Cache Playwright browser id: playwright-cache - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: ~/.cache/ms-playwright key: playwright-${{ runner.os }}-1.58.1-chromium @@ -169,7 +169,7 @@ jobs: - name: Upload artifact if: always() && hashFiles('tmp/visuals/**') != '' - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: ui-visuals-pr-${{ github.event.pull_request.number }} path: tmp/visuals @@ -201,7 +201,7 @@ jobs: fi - name: Upsert sticky comment - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const fs = require('fs') @@ -239,7 +239,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 30 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: ./.github/actions/setup - name: Build packages @@ -253,7 +253,7 @@ jobs: # on a hit we still run install-deps (apt only). (Exploration 0193.) - name: Cache Playwright browser id: playwright-cache - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: ~/.cache/ms-playwright key: playwright-${{ runner.os }}-1.58.1-chromium