Bump actions/checkout off the deprecated v4 in @danielridgebot's workflows
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 88/100
Línea de trabajo
En hackforla/check-ghpages-versions, inspecciona .github/workflows/check-gh-pages-version.yml, check-ruby-version.yml, keepalive.yml y test-issue-labels.yml. Encuentra cada entrada uses: actions/checkout y actualiza solo las cuatro versiones solicitadas; después ejecuta keepalive.yml mediante workflow_dispatch. Se considera completado cuando checkout finaliza correctamente sin una anotación de Node 20; se debe confirmar una ejecución programada de comprobación de versiones después del merge.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Overview
We need to bump actions/checkout from v4 to v5 in all four of @danielridgebot's workflows, because v4 targets Node.js 20 and GitHub is force-running it on Node 24 on every run — when that fallback is withdrawn the workflows break, and this bot's failure mode is silence rather than an alert.
Action Items
The bot's code lives in hackforla/check-ghpages-versions — the org repo, not a personal account (the danielridgebot/check-ghpages-versions URL still resolves, but only as a redirect). The fix is one line per file, delivered as a PR on that repo.
- Bump
actions/checkout@v4toactions/checkout@v5in all four workflows:check-gh-pages-version.yml:13,check-ruby-version.yml:13,keepalive.yml:16,test-issue-labels.yml:11. Line numbers were accurate 2026-08-24 and may drift — find them by theuses: actions/checkoutline. - Leave
actions/github-script@v8alone (line 44 of both check workflows). It already runs on Node 24 and produces no annotation. - Do not go past v5 in this pass, even though v7 is current. v5 is the pure Node 24 bump with no behaviour change. v6 moved the persisted git credential into a separate file, and three of these four workflows depend on that credential to
git pusha commit back to the repo. v7 additionally blocks fork checkouts forpull_request_target/workflow_run. Both are probably fine here, but neither is a one-line change any more — going current is a separate ticket that needs a real push test. - Run
keepalive.ymlon the branch viaworkflow_dispatchand confirm the checkout step succeeds with no Node 20 annotation. It is safe to run at any time: it prints the repo's idle age and exits 0 without committing unless the repo has been idle 50 or more days. - After the PR merges, confirm a scheduled run of
check-gh-pages-version.ymlorcheck-ruby-version.ymlcompletes with no "Node.js 20 is deprecated" annotation. Both run daily (12:00 and 12:15 UTC), so this is a next-day check — it cannot be observed from the branch, because the annotation only appears on the runs that actually do the version check.
Resources/Instructions
- Bot repo: https://github.com/hackforla/check-ghpages-versions — workflows are in
.github/workflows/. - Example of the annotation: https://github.com/hackforla/check-ghpages-versions/actions/runs/32782593141 (
check-ruby-version, 2026-08-24) — "Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4". - Release notes, for the version reasoning above: v5.0.0 (Node 24; requires runner v2.327.1+, which GitHub-hosted runners are well past), v6.0.0, v7.0.0.
- A full end-to-end test exists but has side effects and is not needed for this change: setting
release-versions/github-pages-gem.txtto an older value and dispatchingcheck-gh-pages-version.ymlexercises thegit pushpath, but it also opens a real issue on hackforla/devops with a board card, which then has to be closed and the card deleted. - Related: #180 (re-enabled the bot's disabled workflow and added the keepalive).
- Lenguaje dominante
- PowerShell
- Estrellas
- 8
- Forks
- 10
- Merge medio
- 7 h 30 min
- PR fusionados (30 d)
- 22
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de hackforla/devops
-
Fix CONTRIBUTING.md's "Getting write access" section - it contradicts the fork bot and the wiki Abiertocomplexity: small feature: Onboarding good first issue role: DevOps Engineer size: 1pt
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
-
complexity: small feature: maintenance role: DevOps Engineer size: 1pt
Dificultad 3/5 1-2 días Aptitud para principiantes 58/100
-
complexity: medium feature: security role: DevOps Engineer size: 3pt
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
-
Migrate the Terraform S3 backends off dynamodb_table onto use_lockfile and delete the lock tables Abiertocomplexity: medium feature: maintenance role: DevOps Engineer size: 2pt
Dificultad 5/5 Más de una semana Aptitud para principiantes 45/100
-
complexity: large epic feature: project terraform setup role: DevOps Engineer size: 13+pt
Dificultad 5/5 Más de una semana Aptitud para principiantes 30/100
Todos los issues de hackforla/devops
Issues similares
-
core dependencies
Dificultad 1/5 Menos de una hora Aptitud para principiantes 80/100
-
bug github_actions
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
registrystack/registry-stack#1393 ·
-
module: core
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
bigbluebutton/bigbluebutton#25849 ·
-
bug engine
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
rocky-data/rocky#2181 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100