Migrate GitHub Actions to v7 (checkout, setup-node, upload-artifact) - #173
Merged
Merged
Conversation
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Reviewer's GuideThe PR combines a behavior-preserving migration of checkout, setup-node, and upload-artifact to v7 across both workflows with a new Sequence diagram for outbound donation linkssequenceDiagram
actor Visitor
participant DonatePage
participant DonationsSection
participant Analytics
participant OrganizationWebsite
Visitor->>DonatePage: Open /donate
DonatePage->>DonationsSection: render recipients
alt recipients is empty
DonationsSection-->>Visitor: Show in-progress message and contact link
else recipients are approved
DonationsSection-->>Visitor: Show recipient cards
Visitor->>DonationsSection: Click Donate directly
DonationsSection->>Analytics: donation_click
DonationsSection->>OrganizationWebsite: Open donationUrl
end
File-Level Changes
Assessment against linked issues
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Bump the three actions in tests.yml and production-smoke.yml from v5 to v7 as one coordinated migration. No trigger uses pull_request_target or workflow_run, so checkout v7's fork-PR hardening does not affect these workflows. All three v7 releases run on node24, matching the runtime checkout@v5.1 and setup-node@v5 already use inside the pinned Playwright noble container. Preserves persist-credentials: false on every checkout, the minimal permissions blocks, node-version 24 with npm caching, and the if: always() upload steps with 14-day retention. Closes #89
spizeck
force-pushed
the
chore/actions-v7-89
branch
from
September 25, 2026 14:39
b96fb8b to
1223115
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #89
Summary
Coordinated migration of all three GitHub Actions from v5 to v7 in the two repository workflows (
tests.yml,production-smoke.yml) — 9uses:references total, no other workflow changes.actions/checkoutactions/setup-nodeactions/upload-artifactCompatibility findings (v6 + v7 release notes reviewed)
actions/checkoutv7: the only breaking change blocks fork-PR checkouts underpull_request_target/workflow_runtriggers (hardening; also backported to v6.1). Neither trigger is used anywhere in this repo — triggers arepull_request,push,workflow_dispatch,deployment_status, and cron. v6's credential-file change is moot because every checkout usespersist-credentials: false.actions/setup-nodev7: ESM migration +cache-primary-keyoutputs; removed the dummyNODE_AUTH_TOKENexport (unused here). v6's breaking change limited automatic caching to npm — we already setcache: npmexplicitly.node-version: 24support is unchanged (resolved to Node 24.21.0 in CI).actions/upload-artifactv7: adds opt-in direct (unzipped) single-file uploads viaarchive: false; the ESM migration is internal.name,path,retention-days: 14, andif: always()behavior are unchanged. v6 moved the runtime to node24 requiring runner >= 2.327.1 — CI ran on runner 2.337.0,ubuntu-24.04.runs.using: node24. In container jobs the runner injects its own Node runtime, so the container only needs a compatible glibc —mcr.microsoft.com/playwright:v1.63.0-noble(Ubuntu 24.04, glibc 2.39) qualifies.checkout@v5.1andsetup-node@v5already ran node24 inside this exact container, so the runtime path was already proven. The container tag is unchanged.Security posture preserved
persist-credentials: falseretained on all 3 checkout stepspermissions: contents: readunchanged — nothing broadenedretention-days: 14andif: always()artifact behavior unchangedValidation
actions/*@v7steps executed successfully inside the pinned Playwright container (checkout, setup-node with npm cache, upload-artifact incl. post-steps)Note on the earlier run of this branch
The first push briefly contained the unrelated
/donatecommit (db071ba) because the local HEAD had been moved back tofeat/donate-support-saba-171by concurrent work before this branch was created. The branch was rebased ontomaster(701b06e) and force-pushed; the PR now contains only the migration commit1223115. The e2e failure seen on that first run (resize-scroll"just above footer",fromBottom1324 < 1500) is a real regression belonging to PR #172 — the new footer link makes the footer ~32px taller at every breakpoint — not to this migration. It passed here once the branch carried only master's site code.Post-merge verification required
production-smoke.ymlruns ondeployment_status,schedule, andworkflow_dispatch— none fire for PR branches, so it cannot be exercised here. On this PR it correctly evaluated the Vercel preview'sdeployment_statusevent and skipped via the existingif:gate (check shows "Production smoke tests — skipping"), which exercises the workflow path itself. After merge, trigger oneworkflow_dispatchrun to confirm the Actions path end to end (per the issue's validation section).