ci: bump checkout and setup-node to v5 (unbreak the runner) - #15
Open
Andrew Elkins (andrewelkins) wants to merge 2 commits into
Open
Andrew Elkins (andrewelkins) wants to merge 2 commits into
Andrew Elkins (andrewelkins) wants to merge 2 commits into
Conversation
Both CI jobs fail before running anything:
[command]/usr/local/bin/yarn cache dir
/home/runner/.cache/yarn/v6
##[error]Cache service responded with 400
actions/setup-node@v2 bundles a cache client that calls the retired
GitHub Actions Cache v1 API, so 'cache: yarn' hard-fails on every run.
The Install Dependencies, Lint and Run Tests steps are skipped as a
result -- CI currently validates nothing on this repo.
Bumps actions/checkout v2 -> v4 and actions/setup-node v2 -> v4 in all
three jobs, which moves both onto the current cache service and off the
deprecated Node 12/16 action runtimes. node-version is left at 14.x so
this change is limited to unbreaking the runner.
Copilot started reviewing on behalf of
Andrew Elkins (andrewelkins)
September 8, 2026 17:37
View session
There was a problem hiding this comment.
🟢 Approval recommended
The focused action upgrades are consistently applied and address the obsolete cache integration.
Pull request overview
Updates CI actions to restore functional dependency caching and runner compatibility.
Changes:
- Upgrades
actions/checkoutandactions/setup-nodefrom v2 to v4 across all jobs. - Retains Node.js 14 to keep the fix narrowly scoped.
File summaries
| File | Description |
|---|---|
.github/workflows/ci.yml |
Modernizes actions used by all three CI jobs. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
v4 pins both actions to the Node 20 runtime, which GitHub deprecated on 2025-09-19. Runs were already reporting it: Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-node@v4 checkout@v5 and setup-node@v5 both declare `using: node24`, so the warning goes away instead of moving. Same six lines either way, and the point of this change was to get off deprecated action runtimes. node-version stays at 14.x.
Andrew Elkins (andrewelkins)
marked this pull request as ready for review
September 8, 2026 17:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CI on this repo cannot run. Both jobs die at step 3, before any project code is touched:
actions/setup-node@v2bundles a cache client that talks to the retired GitHub Actions Cache v1 API, socache: yarnfails on every run regardless of what is in the PR. Step outcomes before this change:actions/checkout@v2yarn install --frozen-lockfilenever executes, so CI is currently validating nothing.Change
Bumps
actions/checkoutv2 -> v5 andactions/setup-nodev2 -> v5 across all three jobs. That moves the cache onto the current service and off the deprecated action runtimes.v5 rather than v4: v4 targets the Node 20 runtime, which GitHub deprecated on 2025-09-19, and runs were already reporting
Node.js 20 is deprecated ... being forced to run on Node.js 24. Both v5 majors declareusing: node24. Same six lines, and landing on a runtime that is itself deprecated would undercut the point of the change.node-versionis deliberately left at14.xto keep this change scoped to unbreaking the runner.Result
Tests,Floating Dependencies, andox-security/scanpass. Install Node, Install Dependencies, Lint, and Run Tests all execute for the first time:actions/checkoutThe description above predicted this would surface real failures underneath, and it did. The
try-scenariosmatrix is red on all 9 scenarios, from two pre-existing causes — neither introduced here, both previously invisible.testemfloats to an ESM-only dep —ember-lts-3.20,ember-lts-3.24,ember-classic,ember-default-with-jquery,embroider-safe,embroider-optimized.The scenario install logs
Detected a yarn.lock file. Add useYarn: true to your config/ember-try.js.ember try:oneis running npm and ignoringyarn.lock, sotestem— not a direct dependency — floats from the locked 3.6.0 to 3.21.0. testem 3.19.0 movedexecafrom^1.0.0to^9.6.1(ESM-only) and declaresengines: ^20.19 || ^22.12 || ^24 || >= 26. On Node 14,require('execa')intestem/lib/utils/fileutils.jsthrowsERR_REQUIRE_ESM. The build succeeds; it dies launching the test runner.ember-cli3.28 cannot build modernember-source—ember-release,ember-beta,ember-canary.The repo pins
ember-cli ~3.28.4; those three channels are ember 6.x, which no longer ships the vendor files_initVendorFilesexpects.Both are follow-ups, not blockers —
mainhas no required status checks. Also noted while in this file: theFloating Dependenciesjob runsyarn install --frozen-lockfile, identical totestminus lint, so it has never actually floated anything. Fixing it to--no-lockfilebelongs with thetestemfix, since it would surface the same failure.Opened alongside a dependency-security PR against the same repo that CI could not validate.