release-train: develop -> staging - #123
Merged
Merged
Conversation
…es (#121) * ci: move checkout and setup-python off Node 20 before the fallback goes Every job in this repo emits "Node.js 20 is deprecated ... being forced to run on Node.js 24". That forced run is a TEMPORARY GitHub fallback; when it is withdrawn, every job using these actions fails. MEASURED from each tag's own action.yml, not from release prose: checkout v4.x node20 v5.1.0 / v6.1.0 / v7.0.1 node24 setup-python v5.x node20 v6.0.0 / v6.3.0 / v7.0.0 node24 checkout needs v5+, setup-python v6+. v4.4.0 was published the same day as v5.1.0/v6.1.0/v7.0.1 - the v4 line is maintained but stays on node20, so waiting does not fix it. WHY LATEST, NOT THE MINIMAL v5/v6 HOP: cli already ran exactly these two SHAs before this sweep, so latest is proven in the org, and the fleet converges on ONE pin per action instead of gaining a third variant. Neither v7 breaking change applies - verified per repo, not assumed: * setup-python v7 drops the `pip-install` input - unused anywhere in the org. * checkout v7 blocks fork-PR checkout under pull_request_target/workflow_run - every workflow's resolved triggers were parsed as YAML (not grepped, so a comment naming a trigger cannot be mistaken for using one). No workflow in this repo pairs those triggers with a checkout. This also normalises the pin comments: some lines carried a bare `# v4`, which is a mutable major alias in comment form and not the full-semver convention. Scope here: 3 checkout + 0 setup-python lines across 3 file(s). Verified with `git diff -U0` that no other line changed, and all workflows still parse. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * ci(sync-docs): create-pull-request v8, or this commit breaks the docs sync Bugbot, High, and correct — this commit bumped `actions/checkout` to v7.0.1 in `sync-docs.yml` while leaving `peter-evans/create-pull-request` at v6.1.0 in the same file. Confirmed upstream rather than reasoned about: v7.0.9's release notes say "Fixes an incompatibility with the recently released `actions/checkout@v6`" (issue #4228, PR #4230). checkout v6+ writes credentials under `$RUNNER_TEMP`, and create-pull-request below v7.0.9 then sends a duplicate `Authorization` header and fails the "Open or update PR" step. That failure mode is the bad kind: a sync that never opens a PR files no complaint, so docs would simply have stopped tracking upstream, green. **v8, not v7.0.11**, and the distinction is this commit's whole point: v6.1.0 and v7.0.11 are BOTH `using: node20`, so the minimal compatibility bump would have fixed the clash and left behind exactly the runtime this change exists to remove. v8.0.0 is the first `node24` release. Its only breaking change is requiring Actions Runner v2.327.1+ on SELF-HOSTED runners; every job in this repo is GitHub-hosted, so it does not apply. The pin was verified, not copied: tags `v8.1.1` and `v8` both point at 5f6978faf089d4d20b00c7766989d076bb2fc7f1, and `action.yml` at that exact SHA reads `using: 'node24'`. Swept the other twelve PRs in this migration for the same shape — a file whose checkout was bumped that also pins create-pull-request, which the diff alone does not reveal because the cpr line is unchanged. `sync-docs.yml` is the only one. actionlint clean; YAML parses. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Contributor
Author
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 947bd2a. Configure here.
Contributor
Author
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 947bd2a. Configure here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated promotion by the release train (RFC-0008 D14). Head is the train-managed
release-train/to-stagingbranch (a mirror ofdevelop), so it never collides with a human PR. Merged only when the fr-gate is green.Note
Low Risk
Dependency pin updates only in CI workflows; behavior change is limited to checkout/PR-creation steps, with explicit compatibility notes for the paired bump.
Overview
Bumps pinned GitHub Actions in three docs-related workflows:
actions/checkoutmoves from v4.4.0 to v7.0.1 in preview page coverage, SDK extras check, and upstream docs sync.In
sync-docs.yml,peter-evans/create-pull-requestis upgraded from v6.1.0 to v8.1.1 alongside checkout v7. Inline comments document that checkout v6+ stores credentials under$RUNNER_TEMP, which breaks older create-pull-request versions (duplicateAuthorizationheader), and that v8 is required for the Node 24 runtime goal while remaining safe on GitHub-hosted runners.Reviewed by Cursor Bugbot for commit 947bd2a. Bugbot is set up for automated code reviews on this repo. Configure here.