Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

GitHub Actions versions are stale across most workflows

未关闭
#42 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
68/100
Issue 类型
重构
描述清晰度
描述清楚
活跃度
冷清
技术栈
github-actions, python
领域
ci-cd, devops, release

调研方向

先检查 .github/workflows/ci.yml、release.yml、release-please.yml 和 commitlint.yml,然后阅读每个固定版本 action 从当前 major 到目标 major 之间的发布说明。尤其要仔细验证 release.yml 的 artifact 交接和 PyPI 发布 workflow,并删除已废弃的 setup-micromamba 条目,而不是升级它。适用的 action 已安全更新,并且真实 PR 能够成功重新运行 .github/workflows/ci.yml,即视为完成。

由索引模型根据 Issue 内容生成。

描述

tech-debt

Audited 2026-07-29 (prompted by a similar finding in another toolbox
repo). docs.yml's actions have been bumped to current majors as part of
the same change that fixed the Image sidebar bug (see git history), but
the rest of .github/workflows/ was deliberately left alone — bumping
release.yml touches the real PyPI publish pipeline and deserves its own
careful pass (verify the actual release workflow file, don't just bump
and hope), not a drive-by alongside a docs fix.

Action Pinned Latest (2026-07-29) Where Gap
actions/download-artifact v4 v8 release.yml 4 majors
actions/upload-artifact v4 v7 release.yml 3 majors
actions/checkout v6 v7 ci.yml, release.yml 1 major
actions/setup-python v6 v7 release.yml 1 major
googleapis/release-please-action v4 v5 release-please.yml 1 major
amannn/action-semantic-pull-request v5 v6 commitlint.yml 1 major
mamba-org/setup-micromamba v2 v3 ci.yml 1 major
codecov/codecov-action v6 v7 ci.yml 1 major
pypa/gh-action-pypi-publish release/v1 — release.yml none — floating tag, already tracks latest v1.x

download-artifact and upload-artifact are the standouts — 3-4 majors
behind, both used in release.yml's build→publish artifact handoff. Most
of these actions/* majors turned out to be low-risk (mainly Node.js
runtime bumps: v24 requires Actions Runner ≥ v2.327.1, a non-issue on
GitHub-hosted runners), confirmed while bumping docs.yml, but
download-artifact/upload-artifact v4→v7/v8 haven't been checked for
breaking input/output changes yet — do that before bumping release.yml.

Note: the mamba-org/setup-micromamba row is moot once the separate
conda/micromamba-removal work lands — don't bump that one, just delete it.

Fix

For each remaining workflow file, check that action's release notes
between the pinned and latest major for actual breaking changes (not just
Node runtime bumps), then bump. Do release.yml last and most carefully
— it's the one that actually publishes to PyPI. Re-run
.github/workflows/ci.yml on a real PR after bumping it, since it's the
main test gate.

主要语言
Python
星标
220
派生
30
平均合并
12 天 23 小时
30 天内合并 PR
5

环境准备

我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

petercorke/machinevision-toolbox-python 的其他 Issue

查看 petercorke/machinevision-toolbox-python 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。