From 7eb1b71a5b069b15e31dd179b25c24a3022096b3 Mon Sep 17 00:00:00 2001 From: Kamron Batman <3953314+kamronbatman@users.noreply.github.com> Date: Sun, 14 Jun 2026 09:48:57 -0700 Subject: [PATCH] chore: Update workflow actions to Node 24 runtime + watch github-actions (#2486) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Summary Audit of CI/CD workflows (`.github/workflows/**`, `azure-pipelines.yml`) for outdated actions, focused on the Node 20 → Node 24 runner deprecation. Most actions were already migrated; this PR cleans up the remaining stragglers and closes the gap that let them drift. ## Changes | Action | File(s) | From | To | Reason | |---|---|---|---|---| | `softprops/action-gh-release` | `create-release.yml`, `build-tool-release.yml` | `v2` | `v3` | v2 still runs Node 20; v3 is a pure Node 24 runtime move, inputs unchanged (drop-in) | | `dotnet/nbgv` | `create-release.yml` | `v0.5.1` | `v0.5.2` | Node 24 runtime bump | | `SethCohen/github-releases-to-discord` | `post-release-discord.yml` | `v1.19.0` | `v1.20.0` | Latest; adds manual-dispatch test support | | Dependabot | `dependabot.yml` | nuget only | + `github-actions` (weekly) | Auto-PR future action bumps instead of manual audits | ## Already current (no change) `actions/checkout@v6`, `actions/setup-dotnet@v5`, `actions/upload-artifact@v7`, `actions/download-artifact@v8`, and `signpath/...@v2` are all on current majors running the Node 24 runtime. The Azure tasks (`UseDotNet@2`, `NuGetAuthenticate@1`) are current as well. ## Notes - All target versions verified against GitHub's release API. - `action-gh-release@v3` release notes confirm it's a runtime-only change with no input/behavior changes — safe drop-in for both usages. --- .github/dependabot.yml | 4 ++++ .github/workflows/build-tool-release.yml | 2 +- .github/workflows/create-release.yml | 4 ++-- .github/workflows/post-release-discord.yml | 2 +- 4 files changed, 8 insertions(+), 4 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e4ca311d0..393946bf7 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,3 +9,7 @@ updates: directory: "/" # Location of package manifests schedule: interval: "daily" + - package-ecosystem: "github-actions" + directory: "/" # Watches .github/workflows/** + schedule: + interval: "weekly" diff --git a/.github/workflows/build-tool-release.yml b/.github/workflows/build-tool-release.yml index 69ee42ceb..489bbfa12 100644 --- a/.github/workflows/build-tool-release.yml +++ b/.github/workflows/build-tool-release.yml @@ -149,7 +149,7 @@ jobs: sha256sum build-tool-* > checksums-sha256.txt - name: Create or update release - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@v3 with: tag_name: build-tool-latest name: Build Tool (Latest) diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index a04ed63ab..4a67c6287 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -19,7 +19,7 @@ jobs: with: global-json-file: global.json - name: Compute version - uses: dotnet/nbgv@v0.5.1 + uses: dotnet/nbgv@v0.5.2 id: nbgv - name: Push version tag run: | @@ -28,7 +28,7 @@ jobs: env: GITHUB_TOKEN: ${{ secrets.PERSONAL_ACCESS_TOKEN }} - name: Create Release - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@v3 with: tag_name: ${{ steps.nbgv.outputs.Version }} name: ${{ steps.nbgv.outputs.Version }} diff --git a/.github/workflows/post-release-discord.yml b/.github/workflows/post-release-discord.yml index 34f90e0f2..2bcf8b2a9 100644 --- a/.github/workflows/post-release-discord.yml +++ b/.github/workflows/post-release-discord.yml @@ -10,7 +10,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Post Release on Discord - uses: SethCohen/github-releases-to-discord@v1.19.0 + uses: SethCohen/github-releases-to-discord@v1.20.0 with: webhook_url: ${{ secrets.WEBHOOK_URL }} username: "Release Changelog"