fix(ci-cd): bump github actions to node 24 runtimes - #303
Open
piyushsinghgaur1 wants to merge 3 commits into
Open
fix(ci-cd): bump github actions to node 24 runtimes#303piyushsinghgaur1 wants to merge 3 commits into
piyushsinghgaur1 wants to merge 3 commits into
Conversation
Clears the "Node.js 20 is deprecated" GitHub Actions annotation by moving every first-party action pin to a major whose action.yml declares using: node24. * main.yaml: actions/checkout v4 -> v5, actions/setup-node v4 -> v5 * release.yaml: actions/checkout v4 -> v5, actions/setup-node v4 -> v5, node-version 22 -> 24 (also drops the stale UPDATED to v4 comment) * sync-docs.yaml: both actions/checkout pins v4 -> v5 * trivy.yaml: actions/checkout v4 -> v5 * main.yaml test matrix [22, 24] left unchanged so Node 22 coverage is kept * aquasecurity/trivy-action left SHA-pinned and untouched GH-302
Regenerate package-lock.json from scratch and apply npm audit fix to clear vulnerabilities reported by the Trivy scan. GH-302
Regenerate the lockfile so nested @types/node entries required by @loopback/build are present. npm ci rejected the previous lock as out of sync with package.json. Verified with npm ci under npm 10 and 11. GH-302
|
piyushsinghgaur1
marked this pull request as ready for review
August 18, 2026 08:52
Sourav-kashyap
approved these changes
Aug 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description
The workflows in this repo emit a Node.js 20 deprecation warning on every run:
GitHub has removed Node 20 from its runners and force-runs Node 20 actions on Node 24. Builds still succeed, but the annotation appears on every run and becomes a hard failure once the compatibility shim is dropped.
This moves every affected first-party action onto a major that declares
using: node24, and raises anynode-versionstill below 24.Action pins
.github/workflows/main.yamlactions/checkout@v4actions/checkout@v5.github/workflows/main.yamlactions/setup-node@v4actions/setup-node@v5.github/workflows/release.yamlactions/checkout@v4actions/checkout@v5.github/workflows/release.yamlactions/setup-node@v4actions/setup-node@v5.github/workflows/sync-docs.yamlactions/checkout@v4actions/checkout@v5.github/workflows/sync-docs.yamlactions/checkout@v4actions/checkout@v5.github/workflows/trivy.yamlactions/checkout@v4actions/checkout@v5Node versions
.github/workflows/release.yaml'22''24'Each target major was verified to declare
using: node24by reading itsaction.ymlat the pinned tag.Deliberately unchanged
aquasecurity/trivy-action@<sha>) are untouched; SHA pinning is correct practice and unrelated to the Node runtime.Fixes #302
Type of change
How Has This Been Tested?
using: node24in itsaction.ymlScope of this change: 4 file(s) — 4 files changed, 8 insertions(+), 8 deletions(-). CI configuration only; no application source touched.
The warning can be confirmed gone by running a workflow and checking the run summary's Annotations section.
Checklist: