Skip to content

Bump deprecated CI action pins and drop phantom develop branch references - #19

Merged
dmccoystephenson merged 1 commit into
mainfrom
feature/ci-action-versions-and-branch-drift
Sep 12, 2026
Merged

dmccoystephenson merged 1 commit into
mainfrom
feature/ci-action-versions-and-branch-drift

Conversation

@dmccoystephenson

@dmccoystephenson dmccoystephenson commented Sep 10, 2026 •

Copy link
Copy Markdown
Member

Summary

  • actions/checkout and actions/setup-java are bumped from v4 to v5 in both .github/workflows/build.yml (the build and docker-build jobs) and .github/workflows/release.yml. GitHub has deprecated the Node.js 20 runtime these v4 pins target; the runner currently forces them onto Node.js 24 as a transitional measure, so nothing is broken today, but CI would go red on every branch at once when that measure is withdrawn.
  • The develop branch is removed from the Build workflow's push and pull_request triggers. No develop branch exists in this repository, and none ever has — git branch -r and the GitHub branch list both show only main.
  • The contribution workflow in .github/copilot-instructions.md is corrected from "Branch from develop" / "Open a pull request against develop, not main" to main. CONTRIBUTING.md was already corrected to describe the main-only workflow in PR Fix documentation drift: web API paths and develop-branch references #7, but this file was left behind, so the repository's agent-facing guidance still directed contributors at a branch that does not exist and cannot be targeted by a pull request.
  • application-daemon.properties is added to the src/main/resources/ file list in .github/copilot-instructions.md, which named only application.properties and application-web.properties despite the daemon profile having shipped in 2.0.0-SNAPSHOT-8-8-2026. This is a third, independent drift rather than part of Closes #18; it is carried here because it is a one-line correction in a file already being edited for the develop fix.
  • CHANGELOG.md's [Unreleased] section records all of the above.

No application code is changed by this pull request; the entire diff is CI configuration, agent-facing repository guidance, and the changelog.

Verification

actions/checkout@v5 and actions/setup-java@v5 could not be resolved from within the session that prepared this change, so CI is the anchor for them: an action reference that does not exist fails its job immediately with an unresolvable-action error. Both jobs are green on the PR head (run 34451234149), which confirms both pins resolve.

Beyond the green, the deprecation annotation was compared before and after, since a green run alone would not show the change had its intended effect:

Before, on main (run 34081253074):

build:        actions/checkout@v4, actions/setup-java@v4
docker-build: actions/checkout@v4, docker/build-push-action@v5, docker/setup-buildx-action@v3

After, on this branch (run 34451234149):

build:        (no deprecation annotation)
docker-build: docker/build-push-action@v5, docker/setup-buildx-action@v3

The build job is now clean, and actions/checkout has dropped out of the docker-build annotation as well.

Scope decision: the docker/* pins were deliberately left alone

Issue #18 notes that docker/build-push-action@v5 and docker/setup-buildx-action@v3 are "worth reviewing in the same change". They were reviewed and intentionally not bumped here. The comparison above shows the deprecation does apply to them — they are now the only actions the annotation names — so that residue is real rather than hypothetical. It is not resolved here because the current release of each could not be confirmed from within this session, and bumping a working docker-build job to an unverified version would add risk without addressing the deprecation this pull request exists to resolve.

Issue #20 has been filed to carry that remaining work, recording the same before/after evidence, so that Closes #18 does not drop it.

Test plan

  • mvn test — 54 tests executed, 0 failures, 0 errors, 1 skipped, BUILD SUCCESS
  • The build job passes on this pull request, confirming actions/checkout@v5 and actions/setup-java@v5 resolve and mvn clean verify still succeeds
  • The docker-build job passes, confirming the entrypoint test and the image build are unaffected
  • The deprecation annotations for actions/checkout@v4 and actions/setup-java@v4 no longer appear on the run
  • grep -rniI 'develop' across the working tree returns no remaining reference to the branch, only the CHANGELOG.md entry describing this fix

Two limits of this verification are worth stating. The Build workflow's own trigger change cannot be self-verified: the workflow definition that runs for a pull request is the one on the base branch, so the removal of the develop trigger takes effect only once merged. Since develop does not exist, no run can be lost by it. Separately, .github/workflows/release.yml is not exercised by pull request CI at all — it triggers only on release creation. Its two pins are textually identical to the ones the build job does verify, which is reasonable but indirect evidence; the release workflow itself stays unexercised until the next release is cut.

Merge handling

This pull request modifies .github/workflows/*, which is on this loop's do-not-auto-merge list because CI configuration changes affect the review and automation gates that everything else is verified against. It is therefore left open for maintainer review rather than merged autonomously, even though merging was pre-authorized for this session in general.

Issues not selected this cycle

Also observed, not fixed here

The remote branch feature/docs-accuracy-sweep is left over from PR #10, which was squash-merged without deleting it. Deleting it is unrelated to this change and was not performed.

Closes #18

This PR description was drafted during a Gardener session (https://github.com/Stephenson-Software/gardener).


drafted by Claude on behalf of Daniel Stephenson

…nces

Pin actions/checkout@v5 and actions/setup-java@v5 in both workflows,
replacing the v4 pins GitHub deprecated with the Node.js 20 runtime.

Remove the develop branch from the Build workflow triggers and correct
the contribution workflow in copilot-instructions.md, which still told
contributors to branch from and open pull requests against a branch this
repository has never had. Also list application-daemon.properties among
the resources files.

Closes #18

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dmccoystephenson

Copy link
Copy Markdown
Member Author

Self-review rubric, scored against the diff and CI output rather than judgment. Both jobs of run 34451234149 are green on the PR head.

  • Scope: PASS, with one noted stretch — three of the four files are directly required by CI pins deprecated actions/checkout@v4 and actions/setup-java@v4 in both workflows #18 or the develop drift. The exception is the application-daemon.properties line added to .github/copilot-instructions.md: that is a third, independent drift, not covered by Closes #18. It is a one-line factual correction in a file already being edited for the develop fix, and the repository's own convention requires documentation corrections to travel with the change, so it is retained rather than split — but it is fairly called out as an unrelated rider on this pull request.
  • Tests-new: N/A — no public method or function is added; the diff contains no Java.
  • Tests-fix: PASS, by CI-log comparison rather than stash-and-run — the usual revert-and-rerun is not available for a CI configuration change, so a before/after comparison of the deprecation annotation serves as the empirical anchor. On main (run 34081253074) the annotation read actions/checkout@v4, actions/setup-java@v4 on the build job and actions/checkout@v4, docker/build-push-action@v5, docker/setup-buildx-action@v3 on docker-build. On this branch (run 34451234149) the build job emits no deprecation annotation at all, and actions/checkout has dropped out of the docker-build annotation. The change is therefore confirmed to have had its intended effect, not merely to have left CI green.
  • Sibling renames: PASS — every develop occurrence was renamed together. grep -rniI 'develop' across the working tree, excluding .git, target, and the words development/developed/developer, now returns exactly one hit: the CHANGELOG.md entry describing this fix. Both trigger blocks in build.yml and both contribution-workflow lines in copilot-instructions.md were changed in the same commit.
  • Sibling structure: N/A — no new file is created.
  • Docs: PASS — no CLI flag, JVM system property, configuration key, or REST endpoint changes, so README.md, COMMANDS.md, CONFIG.md and USER_GUIDE.md require no edit; each was re-read against the source this cycle to confirm. CHANGELOG.md's [Unreleased] section records all three changes, split correctly between Changed and Fixed per Keep a Changelog.
  • Issue resolution: FAIL as originally filed, now addressed — CI pins deprecated actions/checkout@v4 and actions/setup-java@v4 in both workflows #18's primary surface area is fully changed, but the issue also asks that the docker/* pins be reviewed in the same change, and the pull request body justified excluding them partly on the grounds that the deprecation annotation did not name them. The CI run above disproves that specific ground: the annotation does name docker/build-push-action@v5 and docker/setup-buildx-action@v3, and after this change they are the only actions it names. The exclusion decision itself still stands, because the current release of each could not be confirmed from within this session and an unverified bump would put a working docker-build job at risk for no gain. To keep Closes #18 from dropping that residue on the floor, issue CI still pins deprecated docker/build-push-action@v5 and docker/setup-buildx-action@v3 #20 has been filed recording the before/after evidence and the remaining pins.
  • CI: PASS — build and docker-build both pass on the PR head (run 34451234149). This anchor is unusually load-bearing here: actions/checkout@v5 and actions/setup-java@v5 could not be resolved from within this session, so the green build job is the evidence that both references exist and work, an unresolvable action reference being a hard job failure.
  • Config-doc parity: N/A — no application*.properties key and no @Value/@ConfigurationProperties field is added or changed.
  • Command-doc parity: N/A — no CLI flag, JVM system property, or REST endpoint is added or changed.
  • Package placement: N/A — no Java source is touched.
  • No credential leakage: PASS — the diff introduces no logging, printing, or persistence of GITHUB_TOKEN or any other secret; it adds no workflow step that echoes the environment.

Two limits of this verification are worth stating plainly. The Build workflow's own trigger change cannot be self-verified, because the workflow definition that runs for a pull request is the one on the base branch; the removal of the develop trigger takes effect only after merge, and since no develop branch exists, no run can be lost by it. Separately, .github/workflows/release.yml is not exercised by pull request CI at all, as it triggers only on release creation — its two pins are textually identical to the ones the build job does verify, which is reasonable but indirect evidence, and the file itself stays unexercised until the next release is cut.

Merge handling is unchanged from the pull request body: .github/workflows/* is on this loop's do-not-auto-merge list, because a CI configuration change alters the gate every other change is verified against. This pull request is therefore left open for maintainer review rather than merged autonomously, notwithstanding the general merge pre-authorization for this session.

This review was posted during a Gardener session (https://github.com/Stephenson-Software/gardener).


drafted by Claude on behalf of Daniel Stephenson

@dmccoystephenson
dmccoystephenson merged commit 6d8f9b1 into main Sep 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI pins deprecated actions/checkout@v4 and actions/setup-java@v4 in both workflows

1 participant