Skip to content

CI & reusable workflows: bump Actions to current majors (checkout v7, setup-uv v10, upload v7, download v8) - #343

Merged
renmengye merged 3 commits into
mainfrom
chore/actions-bump
Sep 8, 2026
Merged

renmengye merged 3 commits into
mainfrom
chore/actions-bump

Conversation

@renmengye

Copy link
Copy Markdown
Member

Digest #332, the mechanical part. Bumps the four pinned actions to their current majors across every workflow.

The one behaviour to watch is download-artifact (v4 → v8). It is safe here: the post jobs download a single named artifact into runner.temp, which stays flat, so runner.temp/findings.json still resolves; the summarizer's pattern download reads **/findings.json recursively, so a per-artifact subdirectory is fine. node24 (required by checkout v5+) is on the hosted runners.

Because these reusable workflows run from @main, a break only shows after merge — so this merges then gets a canary review on a throwaway PR immediately, and I revert if the review does not post. Held for a watched window on purpose.

🤖 Generated with Claude Code

… setup-uv v10, upload v7, download v8)

Mechanical version bump across the workflows. The two artifact-download
shapes are unchanged in behaviour: single-name downloads extract flat into
runner.temp (the post jobs read runner.temp/findings.json), and the
summarizer's pattern download reads **/findings.json recursively, so a
per-artifact subdirectory is fine either way. node24 is on the hosted
runners. Verified by a canary review after merge, revert-ready.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 1 — reviewed head b5a723e4 — reviewer summarizer:hermes/gpt-5.6-terra over coverage+credentials+deployment+general+lifecycle+prose.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: 2 blocking, 0 advisory.

2 findings attached to the lines below.

Blocking verdict: replace astral-sh/setup-uv@v10 in CI and the advisory workflow with an existing, resolvable release ref. The CI occurrence is corroborated by coverage, deployment, lifecycle, and prose; credentials independently identifies the advisory-workflow occurrence. Rejected: coverages statement that upstream tags exist only through v7 is contradicted by the more specific v10.0.0/v10.0.1 evidence; its core non-resolving-v10 finding was retained. The deployment, lifecycle, and prose CI reports were merged as duplicates of the same action reference rather than recorded separately. General reported no findings.

Comment thread .github/workflows/ci.yml Outdated
Comment thread .github/workflows/advisory-review-agent.yml Outdated
…ajor exists)

astral-sh/setup-uv publishes exact releases up to v10.0.1 but only moving
major tags through v7, so @v10 does not resolve. Pin the exact v10.0.1;
checkout@v7, upload-artifact@v7 and download-artifact@v8 keep their moving
majors, which do exist.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@renmengye renmengye added the outerloop:review re-request the advisory review label Sep 8, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 1 — reviewed head 2cf1d2d4 — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: no defects found.

@renmengye
renmengye merged commit 8d73812 into main Sep 8, 2026
2 checks passed
@renmengye
renmengye deleted the chore/actions-bump branch September 8, 2026 19:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

outerloop:review re-request the advisory review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant