CD workflows: pin GitHub Actions to @v4 instead of @master

Open Beginner friendly
#124 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
78/100
Issue type
Refactor
Clarity
Clearly specified
Activity status
Quiet
Tech stack
github-actions
Domain
ci-cd

Research direction

Start with .github/workflows/cd_dev.yaml and .github/workflows/cd_prod.yaml, then compare their action references with tests.yaml and shared_openapi_sync.yaml. Replace the listed @master references with @v4 and verify that no @master references remain under .github/workflows/; CI passing completes the work.

Written by the indexing model from the issue text.

Description

Summary

Our CD workflows pin GitHub Actions to the moving @master branch instead of a stable major-version tag like @v4. Every workflow run silently picks up whatever HEAD of actions/checkout, actions/setup-node, and actions/cache happens to be — there is no diff in this repo when those upstream branches change, so a green PR yesterday can fail today for reasons we cannot see.

Affected workflows

  • .github/workflows/cd_dev.yaml — 5 occurrences (3× actions/checkout@master, 1× actions/setup-node@master, 1× actions/cache@master)
  • .github/workflows/cd_prod.yaml — 2 occurrences of actions/checkout@master

Our newer workflows (tests.yaml, shared_openapi_sync.yaml) already pin actions/checkout@v4 and actions/setup-node@v4, so the inconsistency is internal to this repo too.

Why this matters

  • Reproducibility — same YAML produces different behavior over time.
  • Supply-chain surface — a malicious or accidental commit to actions/checkout's master branch propagates to every run immediately.
  • Breaking changes — when actions/checkout@v5 ships, @master consumers get the breakage at the next run with no warning.
  • GitHub's own guidance explicitly recommends pinning to a major version tag or a SHA. Major-version tags (@v4) still receive patch/security updates automatically.

Cross-repo alignment

  • RERUM v1 (CenterForDigitalHumanities/rerum_server_nodejs) already uses @v4 across all CI/CD workflows.
  • TPEN-services has the same drift — tracked in CenterForDigitalHumanities/TPEN-services#525.
  • TinyPEN has the same drift — tracked in CenterForDigitalHumanities/TinyPen#50.

Proposed fix

Normalize the two CD workflows to:

  • actions/checkout@v4
  • actions/setup-node@v4
  • actions/cache@v4

Small, contained sweep; no behavior changes expected (these are the same versions the existing tests.yaml and shared_openapi_sync.yaml already run on).

Acceptance criteria

  • No @master references remain in .github/workflows/.
  • All actions/checkout, actions/setup-node, actions/cache references in CD workflows pin to @v4.
  • CI passes on the sweep PR.

Out of scope

  • Pinning to commit SHAs — first-party actions/* major-version tags are sufficient.
  • TPEN-services and TinyPEN cleanups — separate issues.
Dominant language
JavaScript
Stars
1
Forks
3
Avg merge
12h 6m
Merged PRs (30d)
2

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from CenterForDigitalHumanities/TinyNode

All issues in CenterForDigitalHumanities/TinyNode

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.