Skip to content

ci: bump checkout and setup-node to v5 (unbreak the runner) - #15

Open
Andrew Elkins (andrewelkins) wants to merge 2 commits into
mainfrom
ci/modernize-actions
Open

Andrew Elkins (andrewelkins) wants to merge 2 commits into
mainfrom
ci/modernize-actions

Conversation

@andrewelkins

@andrewelkins Andrew Elkins (andrewelkins) commented Aug 17, 2026 •

Copy link
Copy Markdown

CI on this repo cannot run. Both jobs die at step 3, before any project code is touched:

[command]/usr/local/bin/yarn cache dir
/home/runner/.cache/yarn/v6
##[error]Cache service responded with 400

actions/setup-node@v2 bundles a cache client that talks to the retired GitHub Actions Cache v1 API, so cache: yarn fails on every run regardless of what is in the PR. Step outcomes before this change:

Step Result
actions/checkout@v2 success
Install Node failure
Install Dependencies skipped
Lint skipped
Run Tests skipped

yarn install --frozen-lockfile never executes, so CI is currently validating nothing.

Change

Bumps actions/checkout v2 -> v5 and actions/setup-node v2 -> v5 across all three jobs. That moves the cache onto the current service and off the deprecated action runtimes.

v5 rather than v4: v4 targets the Node 20 runtime, which GitHub deprecated on 2025-09-19, and runs were already reporting Node.js 20 is deprecated ... being forced to run on Node.js 24. Both v5 majors declare using: node24. Same six lines, and landing on a runtime that is itself deprecated would undercut the point of the change.

node-version is deliberately left at 14.x to keep this change scoped to unbreaking the runner.

Result

Tests, Floating Dependencies, and ox-security/scan pass. Install Node, Install Dependencies, Lint, and Run Tests all execute for the first time:

Step Before After
actions/checkout success success
Install Node failure success
Install Dependencies skipped success
Lint / Run Tests skipped success

The description above predicted this would surface real failures underneath, and it did. The try-scenarios matrix is red on all 9 scenarios, from two pre-existing causes — neither introduced here, both previously invisible.

testem floats to an ESM-only dep — ember-lts-3.20, ember-lts-3.24, ember-classic, ember-default-with-jquery, embroider-safe, embroider-optimized.

The scenario install logs Detected a yarn.lock file. Add useYarn: true to your config/ember-try.js. ember try:one is running npm and ignoring yarn.lock, so testem — not a direct dependency — floats from the locked 3.6.0 to 3.21.0. testem 3.19.0 moved execa from ^1.0.0 to ^9.6.1 (ESM-only) and declares engines: ^20.19 || ^22.12 || ^24 || >= 26. On Node 14, require('execa') in testem/lib/utils/fileutils.js throws ERR_REQUIRE_ESM. The build succeeds; it dies launching the test runner.

ember-cli 3.28 cannot build modern ember-source — ember-release, ember-beta, ember-canary.

TypeError: Cannot read property 'debug' of undefined
    at EmberAddon._initVendorFiles (node_modules/ember-cli/lib/broccoli/ember-app.js:413:38)

The repo pins ember-cli ~3.28.4; those three channels are ember 6.x, which no longer ships the vendor files _initVendorFiles expects.

Both are follow-ups, not blockers — main has no required status checks. Also noted while in this file: the Floating Dependencies job runs yarn install --frozen-lockfile, identical to test minus lint, so it has never actually floated anything. Fixing it to --no-lockfile belongs with the testem fix, since it would surface the same failure.

Opened alongside a dependency-security PR against the same repo that CI could not validate.

Both CI jobs fail before running anything:

    [command]/usr/local/bin/yarn cache dir
    /home/runner/.cache/yarn/v6
    ##[error]Cache service responded with 400

actions/setup-node@v2 bundles a cache client that calls the retired
GitHub Actions Cache v1 API, so 'cache: yarn' hard-fails on every run.
The Install Dependencies, Lint and Run Tests steps are skipped as a
result -- CI currently validates nothing on this repo.

Bumps actions/checkout v2 -> v4 and actions/setup-node v2 -> v4 in all
three jobs, which moves both onto the current cache service and off the
deprecated Node 12/16 action runtimes. node-version is left at 14.x so
this change is limited to unbreaking the runner.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused action upgrades are consistently applied and address the obsolete cache integration.

Pull request overview

Updates CI actions to restore functional dependency caching and runner compatibility.

Changes:

  • Upgrades actions/checkout and actions/setup-node from v2 to v4 across all jobs.
  • Retains Node.js 14 to keep the fix narrowly scoped.
File summaries
File Description
.github/workflows/ci.yml Modernizes actions used by all three CI jobs.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

v4 pins both actions to the Node 20 runtime, which GitHub deprecated on
2025-09-19. Runs were already reporting it:

  Node.js 20 is deprecated. The following actions target Node.js 20 but
  are being forced to run on Node.js 24: actions/checkout@v4,
  actions/setup-node@v4

checkout@v5 and setup-node@v5 both declare `using: node24`, so the
warning goes away instead of moving. Same six lines either way, and the
point of this change was to get off deprecated action runtimes.

node-version stays at 14.x.
@andrewelkins Andrew Elkins (andrewelkins) changed the title ci: bump checkout and setup-node to v4 (unbreak the runner) ci: bump checkout and setup-node to v5 (unbreak the runner) Sep 8, 2026
@andrewelkins
Andrew Elkins (andrewelkins) marked this pull request as ready for review September 8, 2026 17:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants