Bump actions/checkout off the deprecated v4 in @danielridgebot's workflows
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 88/100
Research direction
In hackforla/check-ghpages-versions, inspect .github/workflows/check-gh-pages-version.yml, check-ruby-version.yml, keepalive.yml, and test-issue-labels.yml. Find each uses: actions/checkout entry and update only the four requested versions, then run keepalive.yml via workflow_dispatch. Done means checkout succeeds without a Node 20 annotation; a scheduled version-check run should be confirmed after the merge.
Written by the indexing model from the issue text.
Description
Overview
We need to bump actions/checkout from v4 to v5 in all four of @danielridgebot's workflows, because v4 targets Node.js 20 and GitHub is force-running it on Node 24 on every run — when that fallback is withdrawn the workflows break, and this bot's failure mode is silence rather than an alert.
Action Items
The bot's code lives in hackforla/check-ghpages-versions — the org repo, not a personal account (the danielridgebot/check-ghpages-versions URL still resolves, but only as a redirect). The fix is one line per file, delivered as a PR on that repo.
- Bump
actions/checkout@v4toactions/checkout@v5in all four workflows:check-gh-pages-version.yml:13,check-ruby-version.yml:13,keepalive.yml:16,test-issue-labels.yml:11. Line numbers were accurate 2026-08-24 and may drift — find them by theuses: actions/checkoutline. - Leave
actions/github-script@v8alone (line 44 of both check workflows). It already runs on Node 24 and produces no annotation. - Do not go past v5 in this pass, even though v7 is current. v5 is the pure Node 24 bump with no behaviour change. v6 moved the persisted git credential into a separate file, and three of these four workflows depend on that credential to
git pusha commit back to the repo. v7 additionally blocks fork checkouts forpull_request_target/workflow_run. Both are probably fine here, but neither is a one-line change any more — going current is a separate ticket that needs a real push test. - Run
keepalive.ymlon the branch viaworkflow_dispatchand confirm the checkout step succeeds with no Node 20 annotation. It is safe to run at any time: it prints the repo's idle age and exits 0 without committing unless the repo has been idle 50 or more days. - After the PR merges, confirm a scheduled run of
check-gh-pages-version.ymlorcheck-ruby-version.ymlcompletes with no "Node.js 20 is deprecated" annotation. Both run daily (12:00 and 12:15 UTC), so this is a next-day check — it cannot be observed from the branch, because the annotation only appears on the runs that actually do the version check.
Resources/Instructions
- Bot repo: https://github.com/hackforla/check-ghpages-versions — workflows are in
.github/workflows/. - Example of the annotation: https://github.com/hackforla/check-ghpages-versions/actions/runs/32782593141 (
check-ruby-version, 2026-08-24) — "Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4". - Release notes, for the version reasoning above: v5.0.0 (Node 24; requires runner v2.327.1+, which GitHub-hosted runners are well past), v6.0.0, v7.0.0.
- A full end-to-end test exists but has side effects and is not needed for this change: setting
release-versions/github-pages-gem.txtto an older value and dispatchingcheck-gh-pages-version.ymlexercises thegit pushpath, but it also opens a real issue on hackforla/devops with a board card, which then has to be closed and the card deleted. - Related: #180 (re-enabled the bot's disabled workflow and added the keepalive).
- Dominant language
- PowerShell
- Stars
- 8
- Forks
- 10
- Avg merge
- 7h 30m
- Merged PRs (30d)
- 22
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from hackforla/devops
-
Fix CONTRIBUTING.md's "Getting write access" section - it contradicts the fork bot and the wiki Opencomplexity: small feature: Onboarding good first issue role: DevOps Engineer size: 1pt
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
complexity: small feature: maintenance role: DevOps Engineer size: 1pt
Difficulty 3/5 1-2 days Newbie friendliness 58/100
-
complexity: medium feature: security role: DevOps Engineer size: 3pt
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
Migrate the Terraform S3 backends off dynamodb_table onto use_lockfile and delete the lock tables Opencomplexity: medium feature: maintenance role: DevOps Engineer size: 2pt
Difficulty 5/5 Over a week Newbie friendliness 45/100
-
complexity: large epic feature: project terraform setup role: DevOps Engineer size: 13+pt
Difficulty 5/5 Over a week Newbie friendliness 30/100
All issues in hackforla/devops
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
vicharanashala/fln#564 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
haskell-actions/setup#152 ·
-
feature-request helm
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
gravitational/teleport#69785 ·
-
A cancelled tests run makes the coverage comment workflow fail and reports it as a red check on main Openarea: ci bug perceived difficulty: 3
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Nitjsefnie-Harness-Commons/daedalus#921 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
TencentCloud/Octop#1007 ·