Bump docker/setup-buildx-action to v4 and docker/build-push-action to v7 - #24
Conversation
The docker-build job's two docker/* pins were the last actions in build.yml still declared on the deprecated Node.js 20 runtime; the runner forces them onto Node.js 24 as a transitional measure, so the job is green today but would go red once that measure is withdrawn. Each tag was fetched and its action.yml compared against the pinned one: both new majors switch to node24 and the only interface change is setup-buildx-action@v4 dropping the long-deprecated config, config-inline and install inputs, none of which build.yml uses. The build-push-action inputs build.yml does use (context, push, tags, cache-from, cache-to) are unchanged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Self-review rubric (run 35429038176 on the PR head):
One finding outside the diff, not addressed here: with Summary: two-line CI pin bump with the deprecation annotation confirmed gone; left open for maintainer review because This comment was drafted during a Gardener session (https://github.com/Stephenson-Software/gardener). drafted by Claude on behalf of Daniel Stephenson |
Summary
docker/setup-buildx-actionis bumped fromv3tov4anddocker/build-push-actionfromv5tov7in thedocker-buildjob of.github/workflows/build.yml. After PR Bump deprecated CI action pins and drop phantom develop branch references #19, these were the only two actions in the workflow still declared on the deprecated Node.js 20 runtime; the runner currently forces them onto Node.js 24 as a transitional measure, so the job is green today but would go red once that measure is withdrawn.CHANGELOG.md's[Unreleased]section records the change.No application code is changed by this pull request; the entire diff is two CI pin lines and one changelog line.
Verification of the new pins
Issue #20 asked that the current major of each action be confirmed against upstream before the pins are moved. Since the GitHub releases API was not reachable from this session, the confirmation was done by fetching the tags themselves and reading each
action.yml:git ls-remote --tagson both repositories showsv4(v4.4.1) as the highest major ofdocker/setup-buildx-actionandv7(v7.4.0) as the highest major ofdocker/build-push-action.docker/build-push-action: theaction.ymldiff from the pinnedv5tov7is one added optional input (call) and therunsblock moving fromnode20/dist/index.jstonode24/dist/index.cjs. Every inputbuild.ymlpasses —context,push,tags,cache-from,cache-to— is present and unchanged. Thev6tag is stillnode20, which is whyv6was not chosen.docker/setup-buildx-action: theaction.ymldiff from the pinnedv3tov4removes the long-deprecatedconfig,config-inlineandinstallinputs and movesrunstonode24.build.ymlpasses no inputs to this action, so none of the removals apply.CI on this pull request is the anchor for the rest: an unresolvable action reference fails its job immediately, so a green
docker-buildjob confirms both tags resolve and the image still builds. The remaining Node.js 20 deprecation annotation on thedocker-buildjob is expected to disappear with this change; that can be checked on the run for this PR's head against thedocker-build: docker/build-push-action@v5, docker/setup-buildx-action@v3annotation quoted in #20.Test plan
mvn test— 84 tests executed, 0 failures, 0 errors, 1 skipped (pre-existing),BUILD SUCCESS. No Java is changed, so this only confirms the tree is unaffected.docker-buildjob passes on this pull request, confirmingdocker/setup-buildx-action@v4anddocker/build-push-action@v7resolve and the image builds with the GHA cache configuration unchangedbuildjob passes (unchanged by this PR)Merge handling
This pull request modifies
.github/workflows/*, which is on this loop's do-not-auto-merge list because CI configuration changes affect the review and automation gates that everything else is verified against. It is therefore left open for maintainer review rather than merged autonomously, even though merging was pre-authorized for this session in general.Issues not selected this cycle
Dockerfile) — deferred. The issue presents three mutually exclusive directions and states explicitly that the choice affects release artifact naming and is left to the maintainer.LICENSEfile) — deferred. Resolving it requires choosing a copyright holder and year to place in a license file, which is a legal decision rather than a text-accuracy correction.Also observed, not fixed here
The remote branch
feature/docs-accuracy-sweep, noted in PR #19 as left over from PR #10, was not checked or deleted this cycle either.Closes #20
This PR description was drafted during a Gardener session (https://github.com/Stephenson-Software/gardener).
drafted by Claude on behalf of Daniel Stephenson