Skip to content

CI: update the GitHub actions and modernize the CodeQL workflow - #1383

Merged
gusthoff merged 7 commits into
AdaCore:mainfrom
gusthoff:dev/topic/infrastructure/ci/action-versions/2026-09-18
Sep 18, 2026
Merged

gusthoff merged 7 commits into
AdaCore:mainfrom
gusthoff:dev/topic/infrastructure/ci/action-versions/2026-09-18

Conversation

@gusthoff

Copy link
Copy Markdown
Collaborator

The actions in .github/workflows had fallen behind by up to four major
versions, and the CodeQL workflow had drifted from the current template.

Action versions

One commit per action, so any single one can be reverted on its own:

  • github/codeql-action/* v3 -> v4
  • actions/checkout v4 -> v7
  • actions/setup-python v5 -> v7
  • actions/setup-node v4 -> v7
  • actions/upload-artifact v4 -> v7
  • actions/download-artifact v4 -> v8

CodeQL is the significant one: v3 stopped at 3.30.6 while v4 continued
through 4.38.x, so the scan ran an outdated analyzer and bundle.

The behavior changes in these releases were checked against how the
workflows call them, and none apply: the fork-PR guard in checkout@v7
does not match the one workflow_run job, caching is set explicitly for
setup-node, setup-python's removed pip-install input is unused, and
the artifacts are uploaded zipped and downloaded by name. The required
Node 24 runtime is satisfied by the GitHub-hosted runners.

CodeQL workflow

  • Declares contents: read and security-events: write instead of
    inheriting the repository default, which could be tightened to one that
    withholds the upload permission.
  • autobuild replaced by build-mode: none; both languages are
    interpreted, so it had nothing to build.
  • analyze gets category: "/language:${{ matrix.language }}", so the
    matrix legs are matched as separate analyses.
  • Refreshed job name, supported-language list and documentation link.
  • runs-on: ubuntu-latest kept, with a comment on why it differs from the
    other workflows: the analysis neither builds nor runs the sources.
  • on: [pull_request] deliberately unchanged.

Dependabot

.github/dependabot.yml is new. It covers github-actions only, monthly,
with CI as the commit prefix. Minor and patch updates are grouped into
one pull request; a major arrives on its own so it can be reviewed or held
back separately. The pnpm and pip manifests are not covered — they are
lockfile-pinned and warrant their own discussion.

Validation

Every workflow parses after each commit. The version-bump diff contains no
changed line that is not a uses: line. The Dependabot file was checked
against the documented option schema, and the CodeQL workflow structurally
(no autobuild, build-mode and category in place, permissions exact,
triggers unchanged). The workflows are exercised by this pull request,
which also runs the reworked CodeQL job on both matrix legs.

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com

gusthoff and others added 7 commits September 18, 2026 18:54
The v3 line stopped receiving updates at `3.30.6`, while the v4 line has
continued through `4.38.x`, so the scan runs a year-old analyzer with an
outdated default CodeQL bundle.

The only change at the v4 boundary is the Node 24 runtime, which the
GitHub-hosted runners satisfy. `init`, `autobuild` and `analyze` are
bumped together, since the action rejects a configuration written by a
different version of `init`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v5, v6 and v7 releases move the action to the Node 24 runtime, store
credentials outside `.git/config`, and refuse to check out fork pull
request code from `pull_request_target` and `workflow_run` workflows.

None of that changes behavior here: the runners are GitHub-hosted, no
step runs authenticated git from a container action, and the single
`workflow_run` job checks out `AdaCore/learn-latest-html-pages` at
`gh-pages`, which the new guard does not match.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v6 and v7 releases move the action to the Node 24 runtime and to an
ESM bundle, and drop the `pip-install` input, which these workflows do
not use. The `python-version` input is unchanged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v5 through v7 releases move the action to the Node 24 runtime and to
an ESM bundle, and change when caching is enabled automatically. Every
call site sets `cache: 'pnpm'` and `cache-dependency-path` explicitly,
which takes precedence over the automatic behavior.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v5 through v7 releases move the action to the Node 24 runtime and to
an ESM bundle, and add an `archive` input for uploading a single file
unzipped. That default is unchanged, so the artifacts stay zipped, and
`if-no-files-found`, `retention-days` and `compression-level` keep their
meaning.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The v5 through v8 releases move the action to the Node 24 runtime and to
an ESM bundle, make a digest mismatch fail the run rather than warn, and
skip decompression for artifacts that were not uploaded zipped.

Neither behavior change affects this workflow: the artifacts are
uploaded zipped, and they are downloaded by name, so the v5 change to
the output path of single-artifact-by-ID downloads does not apply
either.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The workflows pin actions to a moving major tag, which only advances
when someone goes looking, and the CodeQL action in particular stops
receiving analyzer updates once its major is superseded.

Add a `github-actions` entry checking monthly. Minor and patch updates
are grouped into one pull request, while a major matches no group and
arrives on its own, so it can be reviewed or held back without blocking
the rest.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gusthoff
gusthoff merged commit db23213 into AdaCore:main Sep 18, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant