Skip to content

Migrate GitHub Actions to v7 (checkout, setup-node, upload-artifact) - #173

Merged
spizeck merged 1 commit into
masterfrom
chore/actions-v7-89
Sep 25, 2026
Merged

spizeck merged 1 commit into
masterfrom
chore/actions-v7-89

Conversation

@spizeck

@spizeck spizeck commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Closes #89

Summary

Coordinated migration of all three GitHub Actions from v5 to v7 in the two repository workflows (tests.yml, production-smoke.yml) — 9 uses: references total, no other workflow changes.

Action Before After
actions/checkout v5 (3 refs) v7
actions/setup-node v5 (3 refs) v7
actions/upload-artifact v5 (3 refs) v7

Compatibility findings (v6 + v7 release notes reviewed)

  • actions/checkout v7: the only breaking change blocks fork-PR checkouts under pull_request_target / workflow_run triggers (hardening; also backported to v6.1). Neither trigger is used anywhere in this repo — triggers are pull_request, push, workflow_dispatch, deployment_status, and cron. v6's credential-file change is moot because every checkout uses persist-credentials: false.
  • actions/setup-node v7: ESM migration + cache-primary-key outputs; removed the dummy NODE_AUTH_TOKEN export (unused here). v6's breaking change limited automatic caching to npm — we already set cache: npm explicitly. node-version: 24 support is unchanged (resolved to Node 24.21.0 in CI).
  • actions/upload-artifact v7: adds opt-in direct (unzipped) single-file uploads via archive: false; the ESM migration is internal. name, path, retention-days: 14, and if: always() behavior are unchanged. v6 moved the runtime to node24 requiring runner >= 2.327.1 — CI ran on runner 2.337.0, ubuntu-24.04.
  • Playwright container: all three v7 actions declare runs.using: node24. In container jobs the runner injects its own Node runtime, so the container only needs a compatible glibc — mcr.microsoft.com/playwright:v1.63.0-noble (Ubuntu 24.04, glibc 2.39) qualifies. checkout@v5.1 and setup-node@v5 already ran node24 inside this exact container, so the runtime path was already proven. The container tag is unchanged.

Security posture preserved

  • persist-credentials: false retained on all 3 checkout steps
  • permissions: contents: read unchanged — nothing broadened
  • No new tokens, credentials, triggers, or jobs
  • retention-days: 14 and if: always() artifact behavior unchanged

Validation

  • Both workflow files parse as valid YAML
  • Diff is limited to the 9 action version bumps — no behavioral edits
  • CI on this PR: Critical website tests ✅ 6m15s, Performance budgets ✅ 4m3s, CodeQL ✅ (actions + javascript-typescript)
  • All actions/*@v7 steps executed successfully inside the pinned Playwright container (checkout, setup-node with npm cache, upload-artifact incl. post-steps)

Note on the earlier run of this branch

The first push briefly contained the unrelated /donate commit (db071ba) because the local HEAD had been moved back to feat/donate-support-saba-171 by concurrent work before this branch was created. The branch was rebased onto master (701b06e) and force-pushed; the PR now contains only the migration commit 1223115. The e2e failure seen on that first run (resize-scroll "just above footer", fromBottom 1324 < 1500) is a real regression belonging to PR #172 — the new footer link makes the footer ~32px taller at every breakpoint — not to this migration. It passed here once the branch carried only master's site code.

Post-merge verification required

production-smoke.yml runs on deployment_status, schedule, and workflow_dispatch — none fire for PR branches, so it cannot be exercised here. On this PR it correctly evaluated the Vercel preview's deployment_status event and skipped via the existing if: gate (check shows "Production smoke tests — skipping"), which exercises the workflow path itself. After merge, trigger one workflow_dispatch run to confirm the Actions path end to end (per the issue's validation section).

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @spizeck, this account has used its review budget of 1,500,000 diff characters for the last 7 days.

You can request another review in 1 hour and 24 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@vercel

vercel Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
seasaba-web Ready Ready Preview Sep 25, 2026 2:39pm UTC

Request Review

@sourcery-ai

sourcery-ai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Reviewer's Guide

The PR combines a behavior-preserving migration of checkout, setup-node, and upload-artifact to v7 across both workflows with a new /donate Support Saba experience, including an owner-approved first-party recipient model, site navigation and SEO integration, outbound donation analytics, documentation, and comprehensive test coverage. Review the workflow runtime compatibility and security invariants separately from the new route’s rendering, link destinations, and empty-registry behavior; production-smoke validation remains a post-merge workflow_dispatch task.

Sequence diagram for outbound donation links

sequenceDiagram
  actor Visitor
  participant DonatePage
  participant DonationsSection
  participant Analytics
  participant OrganizationWebsite

  Visitor->>DonatePage: Open /donate
  DonatePage->>DonationsSection: render recipients
  alt recipients is empty
    DonationsSection-->>Visitor: Show in-progress message and contact link
  else recipients are approved
    DonationsSection-->>Visitor: Show recipient cards
    Visitor->>DonationsSection: Click Donate directly
    DonationsSection->>Analytics: donation_click
    DonationsSection->>OrganizationWebsite: Open donationUrl
  end
Loading

File-Level Changes

Change Details Files
Upgraded all GitHub Actions references from v5 to v7 without changing workflow behavior.
  • Updated checkout, setup-node, and upload-artifact versions in both workflows.
  • Preserved Node 24, npm caching, credential isolation, artifact retention, and always-upload behavior.
  • Review trigger, runner, and container compatibility assumptions for the Node 24 action runtimes.
.github/workflows/tests.yml
.github/workflows/production-smoke.yml
Added a public Support Saba donation-information route with a first-party outbound donation architecture.
  • Added the localized /donate page explaining conservation contributions and direct giving.
  • Added an empty, owner-approved recipient registry and a graceful in-progress state.
  • Added recipient cards with optional donation links, categories, images, and outbound analytics.
  • Linked the route from the footer, trip-planning content, and conservation partners content.
app/(en)/(content)/donate/page.tsx
components/donations/donations-section.tsx
data/donations.ts
components/footer.tsx
app/(en)/(content)/plan-your-trip/page.tsx
components/partners/conservation-partners-section.tsx
lib/analytics.ts
Integrated the new route into SEO, documentation, and automated coverage.
  • Added /donate to the sitemap, route documentation, and LLM metadata.
  • Added accessibility, smoke, link-integrity, locale-routing, SEO, internal-link, and donation component/page tests.
  • Documented the donation_click analytics event and recipient-content safeguards.
app/sitemap.ts
public/llms.txt
docs/ANALYTICS_SEO.md
docs/OPERATIONS.md
tests/e2e/accessibility.spec.ts
tests/e2e/link-integrity.spec.ts
tests/e2e/locale-routing.spec.ts
tests/e2e/smoke.spec.ts
tests/integration/donate.test.tsx
tests/integration/internal-links.test.tsx
tests/unit/seo.test.ts

Assessment against linked issues

Issue Objective Addressed Explanation
#89 Migrate every checkout, setup-node, and upload-artifact reference in tests.yml and production-smoke.yml from v5 to v7. ✅
#89 Preserve the existing workflow behavior and security posture, including checkout credential isolation, read-only permissions, Node 24/npm caching, artifact retention and always-upload behavior, workflow triggers, and the pinned Playwright container. ✅
#89 Validate the migrated Actions path, including green CI and one post-merge workflow_dispatch run of production-smoke.yml. ❌ The PR documents that CI checks and the post-merge production-smoke workflow_dispatch run are still pending. The code changes appear to implement the migration, but the issue's requested validation has not yet been completed.

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Bump the three actions in tests.yml and production-smoke.yml from v5 to
v7 as one coordinated migration. No trigger uses pull_request_target or
workflow_run, so checkout v7's fork-PR hardening does not affect these
workflows. All three v7 releases run on node24, matching the runtime
checkout@v5.1 and setup-node@v5 already use inside the pinned Playwright
noble container.

Preserves persist-credentials: false on every checkout, the minimal
permissions blocks, node-version 24 with npm caching, and the
if: always() upload steps with 14-day retention.

Closes #89
@spizeck
spizeck force-pushed the chore/actions-v7-89 branch from b96fb8b to 1223115 Compare September 25, 2026 14:39

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sourcery assessment

Approved.

@spizeck
spizeck merged commit 1492231 into master Sep 25, 2026
9 checks passed
@spizeck
spizeck deleted the chore/actions-v7-89 branch September 25, 2026 19:17

This branch was successfully deployed

1 active deployment
Preview — 1223115b Deployed Sep 25, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Migrate GitHub Actions to v7 (checkout, setup-node, upload-artifact)

1 participant