docs: move the examples and docs build onto Node 24 - #28
Merged
Merged
Conversation
- examples: actions/github-script v7 -> v9 (node24); the action pin moves @v0.7 -> @v0.8, since the v0.7 tag still nests actions/checkout@v4 and actions/setup-python@v5 (node20) - docs/user: usage pins @v0.7 -> @v0.8, matching the examples; actions/create-github-app-token v1 -> v3 (first node24 major) - docs.yml: actions/setup-node v6 -> v7, node-version '22' -> '24' - CHANGELOG: two entries under [Unreleased] @v0.8 resolves only once the v0.8 tag is pushed, so this should merge right before the v0.8.0 release. Part of QuantEcon/workspace-lectures#68. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
🟡 Changes recommended
The updated example workflows still have insufficient GitHub token permissions for the actions/github-script steps (issue/comment creation), which will cause runtime failures.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
This PR updates the repository’s copied/consumer-facing materials (example workflows, user docs snippets, and the docs build workflow) to align with GitHub’s Node 24 Actions runtime by bumping referenced action versions and the docs build Node version.
Changes:
- Updated example workflows and docs snippets to use
QuantEcon/action-style-guide@v0.8andactions/github-script@v9(Node 24). - Updated GitHub App setup docs to use
actions/create-github-app-token@v3(Node 24). - Updated docs build workflow to use Node 24 (
actions/setup-node@v7,node-version: '24') and recorded the changes in the changelog.
File summaries
| File | Description |
|---|---|
| examples/style-guide-weekly.yml | Bumps the action and github-script versions for Node 24 compatibility. |
| examples/style-guide-comment.yml | Bumps the action and github-script versions for Node 24 compatibility. |
| docs/user/github-app-setup.md | Updates the recommended GitHub App token action major version. |
| docs/user/getting-started.md | Updates workflow snippet pins to the new action release line. |
| docs/user/configuration.md | Updates the bulk-mode snippet pin to @v0.8. |
| docs/user/cli.md | Updates the “specific version” install example to @v0.8. |
| CHANGELOG.md | Adds unreleased entries documenting the Node 24 pin moves for examples/docs and docs build. |
| .github/workflows/docs.yml | Moves the docs build to Node 24 and updates setup-node major. |
Review details
- Files reviewed: 8/8 changed files
- Comments generated: 3
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…the trigger to its event The comment example granted issues: read, but its github-script steps react to the triggering comment and post the result as an issue comment, both of which need issues: write; the weekly example granted no issues permission for its issues.create step. Both now grant issues: write. The Getting Started snippet listened for issues events but tested only the comment body, so issue events always ran as skipped. The example tested github.event.issue.body on every event, which on a comment event is the parent issue, so once an issue mentioned the trigger every later comment re-ran the check; its reaction step also needed a comment id that an issues event does not carry. Both now test the comment on issue_comment events and the issue on issues events, and the example skips the reaction on issues events. Raised by Copilot's review of #28. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…hey replace The earlier [Unreleased] bullets still said @v0.7 and setup-node v6 on Node 22, with later bullets superseding them. Since none of it is released, correct them in place, and note what the new pins ask of consumers: runner v2.327.1+ on self-hosted runners, and NODE_USE_ENV_PROXY=1 for create-github-app-token v3 behind a proxy. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Part of QuantEcon/workspace-lectures#68. An audit of
main(df55c87, still the head when this branch was cut) found Node 20 still pinned in what consumers copy, the two example workflows and thedocs/user/*usage snippets, and the docs build still on Node 22.action.ymlonmainis already clean: it nestsactions/checkout@v5andastral-sh/setup-uv@v7, bothruns.using: node24. So this PR moves only the examples, the usage docs and the docs build. No code changes. After Copilot's review it also corrects two things in the examples that predate it: the permissions they grant, and when they trigger (see below).Merge timing.
@v0.8does not resolve yet. The repository has nov0.8orv0.8.0tag; the newest isv0.7.2, with the floatingv0.7on the same commit. This PR should merge right before the v0.8.0 release, and that release needs to push the floatingv0.8tag (step 9 of the release process in.github/copilot-instructions.md). Merging also redeploys the docs site, becausedocs.ymlruns on pushes tomainthat touchdocs/**, so the site shows@v0.8from the moment this merges.What changed
I read each new pin's
action.ymlat the tag before pinning it:runs.usingat the new tagactions/github-script@v7(node20)@v9node24QuantEcon/action-style-guidegetting-started.md(2),configuration.md(1),github-app-setup.md(2)@v0.7@v0.8composite;mainnests only node24 actions (above)actions/create-github-app-tokengithub-app-setup.md@v1(node20)@v3node24actions/setup-nodedocs.yml@v6(node24)@v7node24Also:
docs.yml:node-version: '22'becomes'24'for thenpx mystmdbuild.docs/user/cli.md: the "Specific version" pip example moves from@v0.7to@v0.8, so every usage pin names the same release line as the examples.CHANGELOG.md: the earlier[Unreleased]entries that said@v0.7andsetup-node@v6on Node 22 are corrected in place (391feb9), since none of it is released, and a new entry records the Node 24 moves. That entry also says what the new pins ask of consumers: a self-hosted runner needs v2.327.1 or later, andcreate-github-app-tokenv3 dropped its own proxy handling, so behindHTTP_PROXYorHTTPS_PROXYthe step also needsNODE_USE_ENV_PROXY=1(both from its v3.0.0 breaking changes).Notes
@v0.7has to move. Thev0.7tag'saction.ymlnestsactions/checkout@v4andactions/setup-python@v5, and both declareruns.using: node20at those tags.require('@actions/github')fails, and redeclaringgetOctokitwithconstorletis aSyntaxError. The three example scripts do neither. They use onlygithub.rest.reactions.createForIssueComment,github.rest.issues.createComment,github.rest.issues.create,context.repoandcontext.payload. v9'ssrc/main.tsstill injectsgithubandcontextas v7 does, and addsgetOctokit.node20, so v3 is its first node24 major. v3.1.0 deprecatedapp-idin favour ofclient-id. v3 still readsapp-idas a fallback (core.getInput("client-id") || core.getInput("app-id")inmain.js), so the snippet works unchanged but will log a deprecation warning. Moving the page toclient-idchanges which secret users store, so I have left that for a separate docs change.docs.ymlpasses onlynode-version.Also corrected, from review (812a51d)
Copilot's review raised three problems in the lines around these pins. All three predate this PR, and all three are in what consumers copy, so they are corrected here:
examples/style-guide-comment.ymlissues: read, but itsgithub-scriptsteps react to the triggering comment and post the result as an issue comment, and both needissues: write. On a plain issue both calls were refused with 403; they only worked on pull requests, throughpull-requests: write.issues: writeexamples/style-guide-weekly.ymlissuespermission for itsissues.createstep (with labels), so the step was refused with 403.issues: writedocs/user/getting-started.mdsnippetissuesevents but tested onlygithub.event.comment.body, so every issue event ran as skipped. QuantEcon/lecture-python-advanced.myst'sstyle-guide.ymlis this snippet verbatim.issue_commentevents and the issue onissueseventsexamples/style-guide-comment.ymltriggergithub.event.issue.bodyon every event. On a comment event that is the parent issue, so once an issue mentioned@qe-style-checker, every later comment on it re-ran the check. Its reaction step also readcontext.payload.comment.id, which anissuesevent does not carry, so the issue-body trigger it advertises failed before the checker ran.issueseventsCHANGELOG.mdrecords both under a### Fixedheading in[Unreleased].Deliberately left alone
docs.yml'sactions/checkout@v5,upload-pages-artifact@v5anddeploy-pages@v5are already on node24 or composite.0.7.2),__version__, and thegit tag -f v0.7example indocs/developer/contributing.md.CHANGELOG.md,TECHNICAL-REVIEW.mdandPLAN.mdare records and stay as they are.Test plan
docs.yml, and every fencedyamlblock in the three changed docs pages.actionlint1.7.12 is clean on the three workflow files. At 812a51d it is also clean on both examples and on the Getting Started snippet extracted from the page.BASE_URL=/action-style-guide npx -y mystmd build --htmlprinted "Built 13 pages for project" and exited 0. The built pages show@v0.8andcreate-github-app-token@v3.docs.ymlon Actions: not run from this branch. It triggers only on pushes tomainand onworkflow_dispatch, and a dispatch would also start the deploy job. Thegithub-pagesenvironment admits onlymain, so that job would be refused, but I did not attempt a deploy from a branch. The merge run, which deploys, is the first real proof.docs.yml.@v0.8resolves only after the release.🤖 Generated with Claude Code