Skip to content

[CI] Pin reviewed Node 24 action releases - #102

Merged
jjangg96 merged 1 commit into
mainfrom
orca/issue-101-node24-actions
Sep 26, 2026
Merged

jjangg96 merged 1 commit into
mainfrom
orca/issue-101-node24-actions

Conversation

@jjangg96

@jjangg96 jjangg96 commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Goal and scope

Refs #101. Replace the old Node 20 action pins with immutable official Node 24 releases, resolving the forced-runtime warnings observed in Public CI run https://github.com/1XP-AI/gh-runnerd/actions/runs/36234842829.

  • actions/checkout v7.0.1: 3d3c42e5aac5ba805825da76410c181273ba90b1
  • actions/setup-go v7.0.0: b7ad1dad31e06c5925ef5d2fc7ad053ef454303e
  • Preserve hosted Ubuntu, Go 1.26.8, read-only permissions, triggers, concurrency, exact checkout refs, PR fetch depth, persist-credentials: false, cache: false, and all existing checks. No unsafe checkout opt-in.
  • Update the existing pin contract and dependency inventory with immutable runtime/license sources. Both actions remain MIT; Node 24 requires Actions Runner >=2.327.1.

Actual validation

Candidate: 883c660a15cec1d1a13e572ac9f9ee89357cfa24.

TDD red: after changing the existing expected pins but before changing workflows, GOTOOLCHAIN=go1.26.8 go test -run '^TestPublicWorkflowCapacityContract$' -count=1 ./scripts exited 1 with eight expected pin mismatches across root/race/offline/vuln jobs.

Green after implementation:

GOTOOLCHAIN=go1.26.8 go test -run '^(TestPublicWorkflowCapacityContract|TestPullRequestQuickWorkflowContract|TestG01WorkflowModuleSelectionPredicate)$' -count=1 ./scripts
GOTOOLCHAIN=go1.26.8 make deps
GOTOOLCHAIN=go1.26.8 make licenses
git diff --check

Focused tests passed (0.301s), all modules verified, one-module license inventory verified, and whitespace checks passed. No local full suite, live runner test, credential operation, or workflow dispatch/replay was performed.

Review and remaining gates

  • Independent GPT-6-Luna max contract review of exact candidate: no broken invariant found. Optional extra PR-specific assertion expansion was triaged once as routine nonblocking test hardening; no current defect reproduced and no follow-up issue warranted.
  • Separate GPT-6-Luna max security-focused review of exact candidate: no actionable findings. Official pinned source confirms checkout auth cleanup with persistence disabled, unsafe-fork protections enabled by default, and setup-go cache restore/save disabled by the explicit cache input. No live operations or tests were performed by the reviewer.
  • Exact-head GitHub Codex review completed with no findings: [CI] Pin reviewed Node 24 action releases #102 (comment) (completed summary: [CI] Pin reviewed Node 24 action releases #102 (comment)). All issue comments, formal reviews and inline comments were inspected; no unresolved findings.
  • Hosted PR quick check passed: https://github.com/1XP-AI/gh-runnerd/actions/runs/36236305046 . Check annotations were empty, including no forced Node 20 runtime warning.
  • Merged as 9636e33781c72c32319db419334f49f1bc1866bc. Automatic postmerge Public CI passed all seven jobs: https://github.com/1XP-AI/gh-runnerd/actions/runs/36236548788 . Every job's check annotations were inspected and empty; the prior forced Node 20 runtime warning is absent. No manual dispatch/replay.

Official release/manifests/licenses and compatibility evidence are recorded in docs/DEPENDENCIES.md. Checkout v7 unsafe-event protection does not change this repository's pull_request trigger; setup-go v7 retains the used inputs. Cache remains disabled.

Rollback: reviewed revert of the resulting merge commit. No G01/G02 live evidence gate or production implementation is claimed complete.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T10:38:54.899951Z 883c660 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@jjangg96

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: 883c660a15

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@jjangg96
jjangg96 merged commit 9636e33 into main Sep 26, 2026
1 check passed
@jjangg96
jjangg96 deleted the orca/issue-101-node24-actions branch September 26, 2026 10:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant