Skip to content

CI: bump GitHub Actions to latest versions - #13

Closed
jnasbyupgrade wants to merge 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:ci/bump-actions-versions
Closed

CI: bump GitHub Actions to latest versions#13
jnasbyupgrade wants to merge 1 commit into
Postgres-Extensions:masterfrom
jnasbyupgrade:ci/bump-actions-versions

Conversation

@jnasbyupgrade

Copy link
Copy Markdown
Contributor

Bump actions/checkout to the latest published major version to clear the Node.js 20 deprecation warnings it was triggering in CI logs.

  • actions/checkout@v4 -> actions/checkout@v7

actions/checkout and other pinned actions had drifted behind their
latest published major version, triggering Node.js deprecation warnings
in CI logs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 140b60b5-c2be-4c99-b7bb-c8125cb37bd7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jnasbyupgrade jnasbyupgrade changed the title ci: bump GitHub Actions to latest versions CI: bump GitHub Actions to latest versions Aug 5, 2026
jnasbyupgrade added a commit that referenced this pull request Aug 9, 2026
* ci: bump Actions pins, add track_progress, add claude-debug label toggle

Combines three related CI-workflow improvements into one PR (touching only
claude-code-review.yml and claude.yml):

- Bump actions/checkout@v4 -> @v7 (current latest major) to clear the
  Node.js-20-deprecation warning it triggers on every run. Supersedes/
  incorporates upstream PR #13 and fork branch ci/bump-actions-versions,
  which made the same v4->v7 bump to the same two lines.
  anthropics/claude-code-action@v1 is still current (a floating v1 tag
  exists at v1.0.185) so it is left as-is.

- Add track_progress: true to the claude-code-action step in
  claude-code-review.yml so it posts a live, updating checklist comment
  as it works instead of staying silent until the whole run finishes --
  which, combined with this workflow's cost gate, could leave a PR dark
  for the better part of an hour. Disabled specifically for
  labeled-triggered runs (see below): the action's own track_progress
  validation only accepts opened/synchronize/reopened/ready_for_review
  for pull_request(_target) events and throws for any other action.

- Add a claude-debug PR-label toggle so a maintainer can skip the cost
  gate and turn on full transcript output (show_full_output) by just
  labeling the PR, without editing/pushing the workflow file. The label
  is queried live via `gh pr view` inside the step rather than read from
  the event payload, since GitHub's "Re-run jobs" replays the original
  stored payload and would miss a label added afterward. `labeled` is
  added to the trigger types so applying the label alone starts a fresh
  run, scoped tightly in the job's `if:` so an unrelated label can't
  re-trigger this paid workflow.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* CI: fix claude-review failing at checkout on every fork PR

actions/checkout now refuses, by default, to check out a fork PR's head
under pull_request_target (a "pwn request" guard) -- this job has always
been safe to opt out of that guard (trusted-fork gate + read-only use),
it just started failing when the guard shipped.

* Fix checkout pattern: don't redirect origin to the fork

allow-unsafe-pr-checkout: true plus a repository:/ref: override checking
out the fork directly is the wrong fix -- it silences the checkout
refusal but breaks claude-code-action's own internal fetch of
refs/pull/<n>/head (which only exists on this repo, not the fork), per
Postgres-Extensions/extension_tools#28 hitting and fixing the identical
mistake. The action already fetches and reads the PR's actual content
itself; this step only needs to check out the base branch.

* CI: register inline-comment MCP tool for claude-code-review

The review step drives claude-code-action with a bare prompt: (no @claude
mention), which runs it in "agent mode". That mode decides which MCP
servers to start from an --allowedTools flag inside claude_args, not from
the invoked plugin's own allowed-tools frontmatter. Without
mcp__github_inline_comment__create_inline_comment listed there, that MCP
server never starts, so the code-review plugin silently falls back to one
consolidated PR comment instead of real per-line inline comments.

* Fold in #26: check PR author (user.login), not head repo owner

head.repo.owner.login only identifies the fork for fork-headed PRs; for
an upstream-branch-headed PR (base and head both in this repo) it's
always this repo's own org, never the actual author, so the gate
silently skipped review on every such PR regardless of who opened it.
user.login is GitHub's own authenticated record of who opened the PR
and isn't attacker-spoofable, so this isn't a weaker check -- it's the
more correct one, and covers both fork-headed and upstream-headed PRs.

* Restore persist-credentials: false on the base-ref checkout

Dropped along with the fork-checkout override, but it's independently
worth keeping: this job never pushes anything, so there's no reason to
leave a push-capable credential in .git/config for the rest of the job.
Matches Postgres-Extensions/pg_count_nulls#53's version of this same fix.

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant