Move every GitHub Action off the retired Node 20 runtime (#995)

GitHub Actions runners no longer ship Node 20 for JavaScript actions, and the
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION opt-out is gone, so any action whose
own action.yml declares `runs.using: node20` (or older) now fails to start.
Each target tag below was verified by reading its action.yml runtime directly,
not inferred from the version number.

  actions/checkout          v3, v4, v6 -> v7
  actions/setup-node        v4         -> v7
  actions/cache             v4         -> v6
  actions/setup-go          v5, v6     -> v7
  docker/metadata-action    v5         -> v6
  docker/login-action       v3         -> v4
  docker/build-push-action  v6         -> v7

booxmedialtd/ws-action-parse-semver is knowingly left alone. It declares node12
at v1, its newest tag v1.4.7 and master are node16, and the repo has not been
touched since 2023, so there is no version to move to. Replacing it is a real
change, not a version bump: it validates through node-semver and fails the job
on a non-semver tag, and the obvious substitutes are weaker. A plain shell
capture accepts the dispatch input's own placeholder default of refs/tags/vX.Y.Z,
and netbirdio/shared-actions/actions/parse-semver falls back to 0.0.0 rather
than failing. Either would let the job run on past the bad version, 404 the
openapi.yml download, and push a commit deleting all 36 generated API pages,
because the curl has no --fail and the Go expander ignores read and parse
errors. That swap needs those guards and its own PR.

Breaking changes across every major crossed were checked against the actual
workflow lines and none apply: setup-node v5/v6 auto-caching needs a
packageManager field package.json does not have (and every call site already
passes cache: 'npm'); setup-node v7 drops a NODE_AUTH_TOKEN export nothing
here uses, as no step sets registry-url; cache v5/v6 and checkout v5 raise the
runner floor, and every job runs on ubuntu-latest or macos-latest; checkout v6
relocates persisted credentials, which generate_api_pages already proves
harmless by pushing over HTTPS on v6 today; checkout v7 blocks fork PR heads
under pull_request_target and workflow_run, neither of which is a trigger in
this repo; metadata-action v6 changes '#' handling in list inputs, and the one
input is a bare image name; build-push-action v7 removes DOCKER_BUILD_NO_SUMMARY
and DOCKER_BUILD_EXPORT_RETENTION_DAYS, neither set anywhere; setup-go v6
reworks toolchain selection, and the only Go dependency here declares go 1.18
against an installed 1.21.

The two pull_request-triggered checkouts that run PR-authored code and never
touch a remote — pr-build and codespell — also stop persisting a token into
the workspace. build_n_push keeps its credentials: the same checkout feeds the
promote step's `git ls-remote origin`, so hardening it needs a job split.

setup-node's node-version stays at 20. That is a real concern separately, since
Node 20 is EOL, but docker/Dockerfile is FROM node:20-slim and build_n_push
builds the Next standalone bundle on the runner and copies it into that image,
so build-time and runtime Node have to move together and be proven by a real
build. It belongs in its own PR.
This commit is contained in:
Eduard Gert
2026-09-24 14:50:53 +02:00
committed by GitHub
parent 47b53bdb7d
commit 4779d75306
5 changed files with 18 additions and 13 deletions
+6 -6
View File
@@ -29,13 +29,13 @@ jobs:
docs_build_n_push:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
# Full history so gen:last-updated / gen:sitemap can read real
# per-file commit dates (a shallow clone would yield wrong dates).
fetch-depth: 0
- uses: actions/setup-node@v4
- uses: actions/setup-node@v7
with:
node-version: '20'
cache: 'npm'
@@ -44,7 +44,7 @@ jobs:
run: npm ci
- name: Restore Next.js build cache
uses: actions/cache@v4
uses: actions/cache@v6
with:
path: .next/cache
key: ${{ runner.os }}-nextjs-${{ hashFiles('package-lock.json') }}-${{ hashFiles('src/**', 'mdx/**', 'next.config.mjs') }}
@@ -56,13 +56,13 @@ jobs:
- name: Docker meta
id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@v6
with:
images: netbirdio/docs.netbird.io
- name: Login to DockerHub
if: github.event_name != 'pull_request'
uses: docker/login-action@v3
uses: docker/login-action@v4
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
@@ -71,7 +71,7 @@ jobs:
# can leave this tag behind, but it cannot change :main (or another
# mutable ref tag).
- name: Docker build and publish immutable image
uses: docker/build-push-action@v6
uses: docker/build-push-action@v7
with:
context: .
file: docker/Dockerfile
+3 -1
View File
@@ -15,7 +15,9 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v3
uses: actions/checkout@v7
with:
persist-credentials: false
- name: codespell
uses: codespell-project/actions-codespell@v2
with:
+3 -3
View File
@@ -32,7 +32,7 @@ jobs:
input_string: ${{ github.event.inputs.tag }}
version_extractor_regex: '\/v(.*)$'
- uses: actions/checkout@v6
- uses: actions/checkout@v7
with:
token: ${{ secrets.DEV_GITHUB_TOKEN }}
@@ -53,7 +53,7 @@ jobs:
run: curl -L -o generator/openapi/openapi.yml "https://raw.githubusercontent.com/netbirdio/netbird/v${{ steps.semver_parser.outputs.fullversion }}/shared/management/http/api/openapi.yml"
- name: Install Go
uses: actions/setup-go@v6
uses: actions/setup-go@v7
with:
go-version: '1.25'
@@ -67,7 +67,7 @@ jobs:
run: rm -rf src/pages/ipa/resources/*
- name: Setup Node.js
uses: actions/setup-node@v4
uses: actions/setup-node@v7
with:
node-version: '20'
cache: 'npm'
+5 -2
View File
@@ -14,12 +14,15 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
# The job runs PR-authored code (npm ci, npm run build); nothing in it
# talks to a remote, so no token needs to sit in the workspace.
persist-credentials: false
- name: Setup Node.js
uses: actions/setup-node@v4
uses: actions/setup-node@v7
with:
node-version: '20'
cache: 'npm'
+1 -1
View File
@@ -43,7 +43,7 @@ jobs:
sleep 1
done
- uses: actions/setup-go@v5
- uses: actions/setup-go@v7
with:
go-version: '1.21'