From 158b94fa32c2178f31edbff4b79cd71b7d91c77f Mon Sep 17 00:00:00 2001 From: Michel Lutz Date: Mon, 21 Sep 2026 10:27:29 -0300 Subject: [PATCH] Change: move the workflow actions to the Node 24 runtime Every run printed the same deprecation notice and was forced onto Node 24 regardless, so the pins were buying nothing but the warning. checkout v4 to v7, setup-python v5 to v7, action-gh-release v2 to v3, codecov-action v5 to v7 -- the latest major of each, which is where dependabot would have landed anyway. Checked what the new majors dropped before jumping, because a major bump taken on faith is how a release workflow breaks at the one moment you need it: checkout v7 only restricts checking out a forked PR under `pull_request_target` and `workflow_run`, neither of which appears here, and setup-python v7 removed the `pip-install` input, which nothing used. `cache: pip`, `body_path`, `files`, `token` and `fail_ci_if_error` are all unchanged. Also restores the `## [Unreleased]` header that folding 1.0.0 removed. AGENTS.md tells every change to write its entry under it, and it was not there to write under. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/ci.yml | 26 +++++++++++++------------- .github/workflows/release.yml | 6 +++--- CHANGELOG.md | 11 +++++++++++ 3 files changed, 27 insertions(+), 16 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index dfaeadf..5cc7bae 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -24,8 +24,8 @@ jobs: # is a claim, not support. python: ["3.10", "3.11", "3.12", "3.13", "3.14"] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: ${{ matrix.python }} cache: pip @@ -36,8 +36,8 @@ jobs: name: Lint runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: "3.12" - run: pip install ruff @@ -50,8 +50,8 @@ jobs: name: Types runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: "3.12" - run: pip install -e . mypy pytest @@ -61,8 +61,8 @@ jobs: name: Generated files are current runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: "3.12" - run: pip install -e . @@ -74,8 +74,8 @@ jobs: name: verify.sh runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: "3.12" - run: pip install -e . pytest pytest-cov ruff mypy build @@ -85,13 +85,13 @@ jobs: name: Coverage runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: "3.12" - run: pip install -e . pytest pytest-cov - run: pytest -q - - uses: codecov/codecov-action@v5 + - uses: codecov/codecov-action@v7 with: token: ${{ secrets.CODECOV_TOKEN }} files: coverage.xml diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index ddd732e..c5e351b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -13,8 +13,8 @@ jobs: contents: write id-token: write # PyPI trusted publishing. No long-lived token in secrets. steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: "3.12" @@ -56,7 +56,7 @@ jobs: [ -s RELEASE_NOTES.md ] || { echo "::error::release notes came out empty"; exit 1; } echo "version=$VERSION" >> "$GITHUB_OUTPUT" - - uses: softprops/action-gh-release@v2 + - uses: softprops/action-gh-release@v3 with: body_path: RELEASE_NOTES.md files: dist/* diff --git a/CHANGELOG.md b/CHANGELOG.md index fd48553..4e26afa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,17 @@ All notable changes to Winged-Python are documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [Unreleased] + +### Changed + +- **The workflow actions moved to the Node 24 runtime** — `actions/checkout` v4 to v7, + `actions/setup-python` v5 to v7, `softprops/action-gh-release` v2 to v3, + `codecov/codecov-action` v5 to v7. Every run was printing a deprecation notice and + being forced onto Node 24 anyway. Nothing here uses what the new majors dropped: + `checkout` v7 only restricts forked-PR checkout under `pull_request_target`, and + `setup-python` v7 removed the `pip-install` input. + ## [1.0.0] - 2026-09-21 Parity with [Winged-Swift](https://github.com/micheltlutz/Winged-Swift) 2.0.0, demonstrated