Skip to content

Update shared actions to Node 24 for GitHub Actions Node 20 deprecation - #54

Merged
pxLi merged 1 commit into
NVIDIA:mainfrom
pxLi:action-node24
Mar 31, 2026
Merged

pxLi merged 1 commit into
NVIDIA:mainfrom
pxLi:action-node24

Conversation

@pxLi

@pxLi pxLi commented Mar 31, 2026

Copy link
Copy Markdown
Member

fix #53

Changes

File Before After
checkout/action.yml actions/checkout@v4 (Node 20) actions/checkout@v6 (Node 24)
pr-description-check/action.yml actions/github-script@v7 (Node 20) actions/github-script@v8 (Node 24)
add-to-project/action.yml actions/add-to-project@v1.0.2 (Node 20, unmaintained) Inline GraphQL via actions/github-script@v8 (Node 24)

Verified in forked repo,
https://github.com/pxLi/spark-rapids-common/actions/runs/23777336303/job/69282009121?pr=7

Signed-off-by: Peixin Li <pxLi@nyu.edu>
@pxLi pxLi self-assigned this Mar 31, 2026
@pxLi
pxLi requested a review from a team as a code owner March 31, 2026 02:22
@pxLi pxLi added the Action label Mar 31, 2026
@greptile-apps

greptile-apps Bot commented Mar 31, 2026

Copy link
Copy Markdown

Greptile Summary

This PR updates three shared GitHub Actions composite actions from Node 20 to Node 24 runtimes to address GitHub's Node 20 deprecation. The changes are:

  • checkout/action.yml: Bumps actions/checkout from v4 → v6 (Node 24)
  • pr-description-check/action.yml: Bumps actions/github-script from v7 → v8 (Node 24)
  • add-to-project/action.yml: Replaces the unmaintained actions/add-to-project@v1.0.2 with an inline GraphQL implementation via actions/github-script@v8, and adds a configurable project-url input (defaulting to the existing NVIDIA project URL)

The migration is well-motivated and the inline GraphQL replacement for add-to-project is a solid approach for avoiding an unmaintained dependency. One correctness issue was found: the inline script does not guard against a null projectV2 response before accessing .id, which would produce an unhelpful TypeError when the project URL is invalid or inaccessible. Additionally, actions/checkout@v6 carries a secondary behavioral change (credential storage in $RUNNER_TEMP) that may require runner ≥ v2.329.0 for Docker container callers.

Confidence Score: 4/5

Safe to merge after addressing the null-dereference in the add-to-project GraphQL script.

The PR is well-structured and verified working in a fork. However, the missing null-check on owner.projectV2 in add-to-project/action.yml is a present defect — if the project URL is misconfigured or inaccessible, the action throws a cryptic TypeError instead of a meaningful failure message. The checkout@v6 credential-persistence note is informational (Docker callers only). Fixing the null-check would bring this to a 5.

add-to-project/action.yml — the owner.projectV2 null-check on line 54 should be addressed before merge.

Important Files Changed

Filename Overview
add-to-project/action.yml Replaces unmaintained actions/add-to-project@v1.0.2 with inline GraphQL via actions/github-script@v8; adds project-url input; missing null-check on owner.projectV2 before accessing .id can cause a cryptic TypeError if the project is not found.
checkout/action.yml Bumps actions/checkout from v4 to v6 for Node 24; v6 also changes credential persistence to $RUNNER_TEMP which may require runner v2.329.0 for Docker-based callers.
pr-description-check/action.yml Straightforward bump of actions/github-script from v7 to v8 (Node 24); no logic changes.

Sequence Diagram

sequenceDiagram
    participant W as Calling Workflow
    participant A as add-to-project/action.yml
    participant GH as GitHub GraphQL API

    W->>A: inputs: token, project-url
    A->>A: Parse project URL (regex)
    A->>GH: query organization/user projectV2(number)
    GH-->>A: { projectV2: { id } } or null
    Note over A: ⚠️ Missing null-check here
    A->>GH: query context.payload issue/PR node_id
    A->>GH: mutation addProjectV2ItemById
    GH-->>A: { item: { id } }
    A->>W: core.info("Added to project …")
Loading

Reviews (1): Last reviewed commit: "Update all common actions to use node24 ..." | Re-trigger Greptile

Comment thread add-to-project/action.yml
Comment thread checkout/action.yml
@pxLi
pxLi merged commit ef3e250 into NVIDIA:main Mar 31, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FEA] Update all actions to use node24

3 participants