From 36122beb45f0bd14122af55211d772ab09ef3cd7 Mon Sep 17 00:00:00 2001 From: gusthoff Date: Fri, 18 Sep 2026 18:54:00 +0200 Subject: [PATCH 1/7] CI: update the CodeQL action to v4 The v3 line stopped receiving updates at `3.30.6`, while the v4 line has continued through `4.38.x`, so the scan runs a year-old analyzer with an outdated default CodeQL bundle. The only change at the v4 boundary is the Node 24 runtime, which the GitHub-hosted runners satisfy. `init`, `autobuild` and `analyze` are bumped together, since the action rejects a configuration written by a different version of `init`. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/codeql-analysis.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index b06f6996a..87de4d874 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -32,7 +32,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@v3 + uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} # If you wish to specify custom queries, you can do so here or in a config file. @@ -43,7 +43,7 @@ jobs: # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). # If this step fails, then you should remove it and run the build manually (see below) - name: Autobuild - uses: github/codeql-action/autobuild@v3 + uses: github/codeql-action/autobuild@v4 # â„šī¸ Command-line programs to run using the OS shell. # 📚 https://git.io/JvXDl @@ -57,4 +57,4 @@ jobs: # make release - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v3 + uses: github/codeql-action/analyze@v4 From 7143abfdcfc229919a6e7606a7305a97eccf6006 Mon Sep 17 00:00:00 2001 From: gusthoff Date: Fri, 18 Sep 2026 18:54:44 +0200 Subject: [PATCH 2/7] CI: update actions/checkout to v7 The v5, v6 and v7 releases move the action to the Node 24 runtime, store credentials outside `.git/config`, and refuse to check out fork pull request code from `pull_request_target` and `workflow_run` workflows. None of that changes behavior here: the runners are GitHub-hosted, no step runs authenticated git from a container action, and the single `workflow_run` job checks out `AdaCore/learn-latest-html-pages` at `gh-pages`, which the new guard does not match. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/code-projects-type-check.yml | 2 +- .github/workflows/codeql-analysis.yml | 2 +- .github/workflows/eslint.js.yml | 2 +- .github/workflows/publish-learn-latest.yml | 2 +- .github/workflows/sphinx-books-tests.js.yml | 4 ++-- .github/workflows/sphinx-content-tests.js.yml | 4 ++-- .github/workflows/sphinx-plugin-tests.js.yml | 2 +- .github/workflows/typescript-tests.js.yml | 4 ++-- .github/workflows/vagrantfile-validation.yml | 4 ++-- 9 files changed, 13 insertions(+), 13 deletions(-) diff --git a/.github/workflows/code-projects-type-check.yml b/.github/workflows/code-projects-type-check.yml index b9ad71d21..f3e4b3766 100644 --- a/.github/workflows/code-projects-type-check.yml +++ b/.github/workflows/code-projects-type-check.yml @@ -20,7 +20,7 @@ jobs: python-version: ['3.14'] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} uses: actions/setup-python@v5 with: diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 87de4d874..4f1c18566 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -28,7 +28,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL diff --git a/.github/workflows/eslint.js.yml b/.github/workflows/eslint.js.yml index 417044d17..d07f2e0ff 100644 --- a/.github/workflows/eslint.js.yml +++ b/.github/workflows/eslint.js.yml @@ -22,7 +22,7 @@ jobs: node-version: [24.x] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} diff --git a/.github/workflows/publish-learn-latest.yml b/.github/workflows/publish-learn-latest.yml index 893b871a0..628881d81 100644 --- a/.github/workflows/publish-learn-latest.yml +++ b/.github/workflows/publish-learn-latest.yml @@ -52,7 +52,7 @@ jobs: github-token: ${{ secrets.LEARN_READ_TOKEN }} - name: Checkout learn-latest-html-pages - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: AdaCore/learn-latest-html-pages ref: gh-pages diff --git a/.github/workflows/sphinx-books-tests.js.yml b/.github/workflows/sphinx-books-tests.js.yml index a6839388b..a461f35e7 100644 --- a/.github/workflows/sphinx-books-tests.js.yml +++ b/.github/workflows/sphinx-books-tests.js.yml @@ -17,12 +17,12 @@ jobs: node-version: [24.x] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} uses: actions/setup-python@v5 with: python-version: ${{ matrix.python-version }} - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} diff --git a/.github/workflows/sphinx-content-tests.js.yml b/.github/workflows/sphinx-content-tests.js.yml index b39f64d6d..2a9f3ceca 100644 --- a/.github/workflows/sphinx-content-tests.js.yml +++ b/.github/workflows/sphinx-content-tests.js.yml @@ -17,12 +17,12 @@ jobs: node-version: [24.x] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} uses: actions/setup-python@v5 with: python-version: ${{ matrix.python-version }} - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} diff --git a/.github/workflows/sphinx-plugin-tests.js.yml b/.github/workflows/sphinx-plugin-tests.js.yml index e9bda4912..374c4273a 100644 --- a/.github/workflows/sphinx-plugin-tests.js.yml +++ b/.github/workflows/sphinx-plugin-tests.js.yml @@ -23,7 +23,7 @@ jobs: python-version: ['3.14'] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} uses: actions/setup-python@v5 with: diff --git a/.github/workflows/typescript-tests.js.yml b/.github/workflows/typescript-tests.js.yml index ba9d738a9..a76cba919 100644 --- a/.github/workflows/typescript-tests.js.yml +++ b/.github/workflows/typescript-tests.js.yml @@ -24,12 +24,12 @@ jobs: node-version: [24.x] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} uses: actions/setup-python@v5 with: python-version: ${{ matrix.python-version }} - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} diff --git a/.github/workflows/vagrantfile-validation.yml b/.github/workflows/vagrantfile-validation.yml index f40051fa5..e419316f1 100644 --- a/.github/workflows/vagrantfile-validation.yml +++ b/.github/workflows/vagrantfile-validation.yml @@ -21,7 +21,7 @@ jobs: runs-on: ubuntu-26.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Check Ruby syntax run: ruby -c Vagrantfile @@ -42,7 +42,7 @@ jobs: runs-on: ubuntu-26.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 # Ubuntu's archive carries no `vagrant` package, so the release is # fetched from HashiCorp and pinned, the way the box version is. From 1966cceef44d161e7768c0351cbd414bf1221828 Mon Sep 17 00:00:00 2001 From: gusthoff Date: Fri, 18 Sep 2026 18:55:39 +0200 Subject: [PATCH 3/7] CI: update actions/setup-python to v7 The v6 and v7 releases move the action to the Node 24 runtime and to an ESM bundle, and drop the `pip-install` input, which these workflows do not use. The `python-version` input is unchanged. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/code-projects-type-check.yml | 2 +- .github/workflows/sphinx-books-tests.js.yml | 2 +- .github/workflows/sphinx-content-tests.js.yml | 2 +- .github/workflows/sphinx-plugin-tests.js.yml | 2 +- .github/workflows/typescript-tests.js.yml | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/code-projects-type-check.yml b/.github/workflows/code-projects-type-check.yml index f3e4b3766..515b98a85 100644 --- a/.github/workflows/code-projects-type-check.yml +++ b/.github/workflows/code-projects-type-check.yml @@ -22,7 +22,7 @@ jobs: steps: - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - name: Install pyright diff --git a/.github/workflows/sphinx-books-tests.js.yml b/.github/workflows/sphinx-books-tests.js.yml index a461f35e7..d77b97ef9 100644 --- a/.github/workflows/sphinx-books-tests.js.yml +++ b/.github/workflows/sphinx-books-tests.js.yml @@ -19,7 +19,7 @@ jobs: steps: - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - uses: actions/checkout@v7 diff --git a/.github/workflows/sphinx-content-tests.js.yml b/.github/workflows/sphinx-content-tests.js.yml index 2a9f3ceca..6eeef98be 100644 --- a/.github/workflows/sphinx-content-tests.js.yml +++ b/.github/workflows/sphinx-content-tests.js.yml @@ -19,7 +19,7 @@ jobs: steps: - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - uses: actions/checkout@v7 diff --git a/.github/workflows/sphinx-plugin-tests.js.yml b/.github/workflows/sphinx-plugin-tests.js.yml index 374c4273a..ca4cc9cb1 100644 --- a/.github/workflows/sphinx-plugin-tests.js.yml +++ b/.github/workflows/sphinx-plugin-tests.js.yml @@ -25,7 +25,7 @@ jobs: steps: - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - name: Install OS Deps diff --git a/.github/workflows/typescript-tests.js.yml b/.github/workflows/typescript-tests.js.yml index a76cba919..8445fdb0c 100644 --- a/.github/workflows/typescript-tests.js.yml +++ b/.github/workflows/typescript-tests.js.yml @@ -26,7 +26,7 @@ jobs: steps: - uses: actions/checkout@v7 - name: Set up Python ${{ matrix.python-version }} - uses: actions/setup-python@v5 + uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} - uses: actions/checkout@v7 From 718b52082430ab4a760dd8d0249ceda00dcc65fb Mon Sep 17 00:00:00 2001 From: gusthoff Date: Fri, 18 Sep 2026 18:55:47 +0200 Subject: [PATCH 4/7] CI: update actions/setup-node to v7 The v5 through v7 releases move the action to the Node 24 runtime and to an ESM bundle, and change when caching is enabled automatically. Every call site sets `cache: 'pnpm'` and `cache-dependency-path` explicitly, which takes precedence over the automatic behavior. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/eslint.js.yml | 2 +- .github/workflows/sphinx-books-tests.js.yml | 2 +- .github/workflows/sphinx-content-tests.js.yml | 2 +- .github/workflows/typescript-tests.js.yml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/eslint.js.yml b/.github/workflows/eslint.js.yml index d07f2e0ff..4ed59644a 100644 --- a/.github/workflows/eslint.js.yml +++ b/.github/workflows/eslint.js.yml @@ -26,7 +26,7 @@ jobs: - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} cache: 'pnpm' diff --git a/.github/workflows/sphinx-books-tests.js.yml b/.github/workflows/sphinx-books-tests.js.yml index d77b97ef9..ead32c24a 100644 --- a/.github/workflows/sphinx-books-tests.js.yml +++ b/.github/workflows/sphinx-books-tests.js.yml @@ -26,7 +26,7 @@ jobs: - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} cache: 'pnpm' diff --git a/.github/workflows/sphinx-content-tests.js.yml b/.github/workflows/sphinx-content-tests.js.yml index 6eeef98be..29d96cb08 100644 --- a/.github/workflows/sphinx-content-tests.js.yml +++ b/.github/workflows/sphinx-content-tests.js.yml @@ -26,7 +26,7 @@ jobs: - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} cache: 'pnpm' diff --git a/.github/workflows/typescript-tests.js.yml b/.github/workflows/typescript-tests.js.yml index 8445fdb0c..7491ae772 100644 --- a/.github/workflows/typescript-tests.js.yml +++ b/.github/workflows/typescript-tests.js.yml @@ -33,7 +33,7 @@ jobs: - name: Enable Corepack run: corepack enable - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ matrix.node-version }} cache: 'pnpm' From 378bac522e318be429173f98888595f68772c0cf Mon Sep 17 00:00:00 2001 From: gusthoff Date: Fri, 18 Sep 2026 18:55:49 +0200 Subject: [PATCH 5/7] CI: update actions/upload-artifact to v7 The v5 through v7 releases move the action to the Node 24 runtime and to an ESM bundle, and add an `archive` input for uploading a single file unzipped. That default is unchanged, so the artifacts stay zipped, and `if-no-files-found`, `retention-days` and `compression-level` keep their meaning. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/sphinx-books-tests.js.yml | 4 ++-- .github/workflows/sphinx-content-tests.js.yml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/sphinx-books-tests.js.yml b/.github/workflows/sphinx-books-tests.js.yml index ead32c24a..8c443efb7 100644 --- a/.github/workflows/sphinx-books-tests.js.yml +++ b/.github/workflows/sphinx-books-tests.js.yml @@ -71,7 +71,7 @@ jobs: - name: Build PDF books including build/runtime output run: make HIDDEN_BOOKS="" HIDDEN_CONTENTS="" pdf_books - name: Archive PDF books in artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: learn-pdf-books path: | @@ -82,7 +82,7 @@ jobs: - name: Build EPUB books including build/runtime output run: make HIDDEN_BOOKS="" HIDDEN_CONTENTS="" epub_books - name: Archive EPUB books in artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: learn-epub-books path: | diff --git a/.github/workflows/sphinx-content-tests.js.yml b/.github/workflows/sphinx-content-tests.js.yml index 29d96cb08..840ace68a 100644 --- a/.github/workflows/sphinx-content-tests.js.yml +++ b/.github/workflows/sphinx-content-tests.js.yml @@ -57,7 +57,7 @@ jobs: - name: Build HTML content run: make HIDDEN_BOOKS="" HIDDEN_CONTENTS="" cleanall webpack-production sphinx-production - name: Archive HTML content in artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: learn-html path: | From 0de8b5c4c06f483ffcc2edc0e2ee34e5d2983515 Mon Sep 17 00:00:00 2001 From: gusthoff Date: Fri, 18 Sep 2026 18:56:31 +0200 Subject: [PATCH 6/7] CI: update actions/download-artifact to v8 The v5 through v8 releases move the action to the Node 24 runtime and to an ESM bundle, make a digest mismatch fail the run rather than warn, and skip decompression for artifacts that were not uploaded zipped. Neither behavior change affects this workflow: the artifacts are uploaded zipped, and they are downloaded by name, so the v5 change to the output path of single-artifact-by-ID downloads does not apply either. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/publish-learn-latest.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/publish-learn-latest.yml b/.github/workflows/publish-learn-latest.yml index 628881d81..1ac8b2e7b 100644 --- a/.github/workflows/publish-learn-latest.yml +++ b/.github/workflows/publish-learn-latest.yml @@ -28,7 +28,7 @@ jobs: echo "content_run_id=$content_run_id" >> $GITHUB_OUTPUT - name: Download HTML artifact - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: learn-html path: unzipped_html @@ -36,7 +36,7 @@ jobs: github-token: ${{ secrets.LEARN_READ_TOKEN }} - name: Download PDF books artifact - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: learn-pdf-books path: unzipped_pdf_books @@ -44,7 +44,7 @@ jobs: github-token: ${{ secrets.LEARN_READ_TOKEN }} - name: Download EPUB books artifact - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: learn-epub-books path: unzipped_epub_books From c1deaf00735701ed9fc80ba9e745e6a5cf7c1b74 Mon Sep 17 00:00:00 2001 From: gusthoff Date: Fri, 18 Sep 2026 19:05:35 +0200 Subject: [PATCH 7/7] CI: let Dependabot track the action versions The workflows pin actions to a moving major tag, which only advances when someone goes looking, and the CodeQL action in particular stops receiving analyzer updates once its major is superseded. Add a `github-actions` entry checking monthly. Minor and patch updates are grouped into one pull request, while a major matches no group and arrives on its own, so it can be reviewed or held back without blocking the rest. Co-Authored-By: Claude Opus 5 (1M context) --- .github/dependabot.yml | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 000000000..da58a776f --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,29 @@ +# The workflows pin actions to a moving major tag, which only advances +# when someone goes looking. Dependabot opens the pull request instead, +# so a new major is a decision to take rather than a discovery to make. + +version: 2 + +updates: + - package-ecosystem: "github-actions" + # For Actions this is the documented value rather than a literal + # path: Dependabot searches `.github/workflows` and a root + # `action.yml`. + directory: "/" + schedule: + interval: "monthly" + commit-message: + # Dependabot appends the colon, giving `CI: bump ...`, which is + # the subject convention for infrastructure changes here. + prefix: "CI" + groups: + # Minor and patch updates need no migration, so they travel + # together. Major updates deliberately match no group: each one + # gets its own pull request, and can be reviewed, held back or + # reverted without disturbing the others. + actions-minor-and-patch: + patterns: + - "*" + update-types: + - "minor" + - "patch"