Bump deprecated CI action pins and drop phantom develop branch references - #19
Conversation
…nces Pin actions/checkout@v5 and actions/setup-java@v5 in both workflows, replacing the v4 pins GitHub deprecated with the Node.js 20 runtime. Remove the develop branch from the Build workflow triggers and correct the contribution workflow in copilot-instructions.md, which still told contributors to branch from and open pull requests against a branch this repository has never had. Also list application-daemon.properties among the resources files. Closes #18 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Self-review rubric, scored against the diff and CI output rather than judgment. Both jobs of run 34451234149 are green on the PR head.
Two limits of this verification are worth stating plainly. The Merge handling is unchanged from the pull request body: This review was posted during a Gardener session (https://github.com/Stephenson-Software/gardener). drafted by Claude on behalf of Daniel Stephenson |
Summary
actions/checkoutandactions/setup-javaare bumped fromv4tov5in both.github/workflows/build.yml(thebuildanddocker-buildjobs) and.github/workflows/release.yml. GitHub has deprecated the Node.js 20 runtime thesev4pins target; the runner currently forces them onto Node.js 24 as a transitional measure, so nothing is broken today, but CI would go red on every branch at once when that measure is withdrawn.developbranch is removed from theBuildworkflow'spushandpull_requesttriggers. Nodevelopbranch exists in this repository, and none ever has —git branch -rand the GitHub branch list both show onlymain..github/copilot-instructions.mdis corrected from "Branch fromdevelop" / "Open a pull request againstdevelop, notmain" tomain.CONTRIBUTING.mdwas already corrected to describe themain-only workflow in PR Fix documentation drift: web API paths and develop-branch references #7, but this file was left behind, so the repository's agent-facing guidance still directed contributors at a branch that does not exist and cannot be targeted by a pull request.application-daemon.propertiesis added to thesrc/main/resources/file list in.github/copilot-instructions.md, which named onlyapplication.propertiesandapplication-web.propertiesdespite the daemon profile having shipped in2.0.0-SNAPSHOT-8-8-2026. This is a third, independent drift rather than part ofCloses #18; it is carried here because it is a one-line correction in a file already being edited for thedevelopfix.CHANGELOG.md's[Unreleased]section records all of the above.No application code is changed by this pull request; the entire diff is CI configuration, agent-facing repository guidance, and the changelog.
Verification
actions/checkout@v5andactions/setup-java@v5could not be resolved from within the session that prepared this change, so CI is the anchor for them: an action reference that does not exist fails its job immediately with an unresolvable-action error. Both jobs are green on the PR head (run 34451234149), which confirms both pins resolve.Beyond the green, the deprecation annotation was compared before and after, since a green run alone would not show the change had its intended effect:
Before, on
main(run 34081253074):After, on this branch (run 34451234149):
The
buildjob is now clean, andactions/checkouthas dropped out of thedocker-buildannotation as well.Scope decision: the
docker/*pins were deliberately left aloneIssue #18 notes that
docker/build-push-action@v5anddocker/setup-buildx-action@v3are "worth reviewing in the same change". They were reviewed and intentionally not bumped here. The comparison above shows the deprecation does apply to them — they are now the only actions the annotation names — so that residue is real rather than hypothetical. It is not resolved here because the current release of each could not be confirmed from within this session, and bumping a workingdocker-buildjob to an unverified version would add risk without addressing the deprecation this pull request exists to resolve.Issue #20 has been filed to carry that remaining work, recording the same before/after evidence, so that
Closes #18does not drop it.Test plan
mvn test— 54 tests executed, 0 failures, 0 errors, 1 skipped,BUILD SUCCESSbuildjob passes on this pull request, confirmingactions/checkout@v5andactions/setup-java@v5resolve andmvn clean verifystill succeedsdocker-buildjob passes, confirming the entrypoint test and the image build are unaffectedactions/checkout@v4andactions/setup-java@v4no longer appear on the rungrep -rniI 'develop'across the working tree returns no remaining reference to the branch, only theCHANGELOG.mdentry describing this fixTwo limits of this verification are worth stating. The
Buildworkflow's own trigger change cannot be self-verified: the workflow definition that runs for a pull request is the one on the base branch, so the removal of thedeveloptrigger takes effect only once merged. Sincedevelopdoes not exist, no run can be lost by it. Separately,.github/workflows/release.ymlis not exercised by pull request CI at all — it triggers only on release creation. Its two pins are textually identical to the ones thebuildjob does verify, which is reasonable but indirect evidence; the release workflow itself stays unexercised until the next release is cut.Merge handling
This pull request modifies
.github/workflows/*, which is on this loop's do-not-auto-merge list because CI configuration changes affect the review and automation gates that everything else is verified against. It is therefore left open for maintainer review rather than merged autonomously, even though merging was pre-authorized for this session in general.Issues not selected this cycle
Dockerfile) — deferred. The issue presents three mutually exclusive directions and states explicitly that the choice affects release artifact naming and is left to the maintainer. Picking one autonomously would decide a question the issue was filed to put to a human.LICENSEfile) — deferred. Resolving it requires choosing a copyright holder and year to place in a license file, which is a legal decision rather than a text-accuracy correction.Also observed, not fixed here
The remote branch
feature/docs-accuracy-sweepis left over from PR #10, which was squash-merged without deleting it. Deleting it is unrelated to this change and was not performed.Closes #18
This PR description was drafted during a Gardener session (https://github.com/Stephenson-Software/gardener).
drafted by Claude on behalf of Daniel Stephenson