Skip to content

Pin GitHub Actions to Node 24 runtime releases - #243

Merged
HomenShum merged 1 commit into
mainfrom
codex/actions-node24-runtime
Jul 22, 2026
Merged

Pin GitHub Actions to Node 24 runtime releases#243
HomenShum merged 1 commit into
mainfrom
codex/actions-node24-runtime

Conversation

@HomenShum

@HomenShum HomenShum commented Jul 22, 2026

Copy link
Copy Markdown
Owner

What changed

  • Pin actions/checkout to verified commit 3d3c42e5aac5ba805825da76410c181273ba90b1 (v7.0.1).
  • Pin actions/setup-node to verified commit 820762786026740c76f36085b0efc47a31fe5020 (v7.0.0).
  • Pin actions/setup-python to verified commit 5fda3b95a4ea91299a34e894583c3862153e4b97 (v7.0.0).
  • Pin actions/upload-artifact to verified commit 043fb46d1a93c77aae656e7c1c64a875d1fc6a0a (v7.0.1).
  • Pin actions/github-script to verified commit 3a2844b7e9c422d3c10d287c895573f7108da1b3 (v9.0.0).
  • Apply the same immutable pins to the Proof Loop installer template.
  • Bind Node Platform conformance to warning-free producer merge 5c9aa6443ca8e61dc8886fbf0a0b4a7b72858e63 from node-platform#8.
  • Add regression tests that reject action-pin drift and reusable-producer rollback.

Why

The previous JavaScript actions declared the deprecated Node 20 runtime. GitHub was forcing them onto Node 24 and annotating NodeRoom CI, scaffold, and reusable conformance checks. The official pinned releases declare node24; immutable SHAs also remove mutable-tag supply-chain drift.

Validation

  • Official GitHub release tags resolved to the pinned commits; all five commits have valid verification and each action.yml declares node24.
  • Node Platform PR Animated README walkthroughs — live-captured, Remotion-rendered, skill-packaged (+ returning-visitor layout fix) #8 passed, merged, and its exact-main quality run completed with zero annotations.
  • All 9 NodeRoom workflow/template YAML files parsed successfully.
  • Focused regression suite: 5/5 passed after the final setup-python pin.
  • Full local floor: 372 test files, 2,566 tests passed; root and Convex TypeScript checks passed.
  • Commit accuracy gate passed.

@vercel

vercel Bot commented Jul 22, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
noderoom Ready Ready Preview, Comment Jul 22, 2026 12:21pm

Request Review

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown

Scaffold Handoff — For Your Coding Agent

Your coding agent (Codex, Claude Code, etc.) should apply the accepted
scaffold proposals below. Do NOT touch any immutable files.

Immutability Check

Mode: advisory

⚠️ Immutable proof files changed: .github/workflows/ci.yml, .github/workflows/design-gate.yml, .github/workflows/node-platform-conformance.yml, .github/workflows/proofloop-gate.yml, .github/workflows/proofloop-suites.yml, .github/workflows/proofloop.yml, .github/workflows/refresh-design-baselines.yml, .github/workflows/scaffold-check.yml

This is advisory because the check is not running in strict scaffold-repair mode.
If this PR is applying accepted scaffold proposals, rerun with --strict-immutability
and reject the PR unless the immutable changes are removed.

Immutable files guarded during scaffold repair:

  • scripts/proofloop.mjs
  • scripts/agent-improvement-loop.ts
  • tests/harnessChangeEval.test.ts
  • .github/workflows/
  • src/eval/evalTrustPolicy.ts
  • src/eval/architectureBudget.ts
  • evals/evalStore.ts

Changed Files

  • .github/workflows/ci.yml
  • .github/workflows/design-gate.yml
  • .github/workflows/node-platform-conformance.yml
  • .github/workflows/proofloop-gate.yml
  • .github/workflows/proofloop-suites.yml
  • .github/workflows/proofloop.yml
  • .github/workflows/refresh-design-baselines.yml
  • .github/workflows/scaffold-check.yml
  • docs/eval/OFFICIAL_BENCHMARK_READINESS.md
  • docs/eval/OFFICIAL_BENCHMARK_TASK_COVERAGE.md
  • docs/eval/OPENROUTER_CONVEX_BENCHMARK.md
  • docs/eval/agent-improvement-loop.md
  • docs/eval/agent-improvement-loop.svg
  • docs/eval/agent-improvement-loop/20260722T122020Z.json
  • docs/eval/agent-improvement-loop/latest.json
  • docs/eval/agent-workspace-sandbox-smoke.json
  • docs/eval/algorithm-artifact-smoke.json
  • docs/eval/bankertoolbench-official-contract.json
  • docs/eval/docker-sandbox-probe.json
  • docs/eval/eval-runs.jsonl
  • docs/eval/halo-convex-context-telemetry.json
  • docs/eval/halo-self-improvement-smoke.json
  • docs/eval/halo-variant-selection.json
  • docs/eval/official-benchmark-readiness.json
  • docs/eval/official-benchmark-task-coverage.json
  • docs/eval/openrouter-convex-benchmark.json
  • docs/eval/professional-catalog-proofs.json
  • docs/eval/professional-proof-ledger.json
  • docs/eval/spreadsheetbench-chart-visual-probe.json
  • docs/eval/traces/credit/20260722T122027961Z-36fc9c9b_dirty.f04f55d8a16f0154/cascade-healthy.json
  • docs/eval/traces/credit/20260722T122027961Z-36fc9c9b_dirty.f04f55d8a16f0154/delta-incomplete.json
  • docs/eval/traces/credit/20260722T122027961Z-36fc9c9b_dirty.f04f55d8a16f0154/mapping-correct.json
  • docs/eval/traces/credit/20260722T122027961Z-36fc9c9b_dirty.f04f55d8a16f0154/mapping-misbind.json
  • docs/eval/traces/credit/20260722T122027961Z-36fc9c9b_dirty.f04f55d8a16f0154/summit-stressed.json
  • docs/eval/traces/ladder/20260722T122027482Z-36fc9c9b_dirty.f75d1bba59c2e4b9/ladder_L1_read_scripted.json
  • docs/eval/traces/ladder/20260722T122027482Z-36fc9c9b_dirty.f75d1bba59c2e4b9/ladder_L2_edit_scripted.json
  • docs/eval/traces/ladder/20260722T122027482Z-36fc9c9b_dirty.f75d1bba59c2e4b9/ladder_L3_conflict_scripted.json
  • docs/eval/traces/ladder/20260722T122027482Z-36fc9c9b_dirty.f75d1bba59c2e4b9/ladder_L4_blocked_scripted.json
  • docs/eval/traces/ladder/20260722T122027482Z-36fc9c9b_dirty.f75d1bba59c2e4b9/ladder_L5_large_range_scripted.json
  • docs/eval/traces/ladder/20260722T122027482Z-36fc9c9b_dirty.f75d1bba59c2e4b9/ladder_L6_long_horizon_scripted.json
  • docs/eval/traces/ladder/20260722T122027482Z-36fc9c9b_dirty.f75d1bba59c2e4b9/ladder_L7_resume_scripted.json
  • proofloop/templates/github-proofloop-gate.yml
  • tests/githubActionsRuntimePins.test.ts
  • tests/proofloopCi.test.ts

Needs Adversarial Review — Do NOT Apply Yet

These proposals passed the reject check but have not been approved by
an adversarial reviewer. A human or frozen LLM judge must approve them first.

  • scaf-001 (AGENTS.md): Add explicit instruction for step spreadsheetbench-runner-fixture: Step spreadsheetbench-runner-fixture failed — scaffold may need explicit instruction or evidence assertion.
  • scaf-002 (AGENTS.md): Add explicit instruction for step convex-boundaries: Step convex-boundaries failed — scaffold may need explicit instruction or evidence assertion.

Safety Boundary

Agent may improve the scaffold.
Agent may NOT weaken the proof gate.

Immutable files (never modify):

  • scripts/proofloop.mjs
  • scripts/agent-improvement-loop.ts
  • tests/harnessChangeEval.test.ts
  • .github/workflows/
  • src/eval/evalTrustPolicy.ts
  • src/eval/architectureBudget.ts
  • evals/evalStore.ts

Scaffold files (safe to modify):

  • AGENTS.md
  • CLAUDE.md
  • proofloop/scenarios/*.yaml
  • proofloop/rubrics/*.yaml
  • proofloop/subagents/*.md
  • proofloop/adapters/*.js
  • .proofloop/memory.jsonl
  • src/nodeagent/models/prompts/systemPrompt.ts

@HomenShum
HomenShum force-pushed the codex/actions-node24-runtime branch from 3f70887 to 978c027 Compare July 22, 2026 12:19
@HomenShum
HomenShum merged commit 83f9b74 into main Jul 22, 2026
12 checks passed
@HomenShum
HomenShum deleted the codex/actions-node24-runtime branch July 22, 2026 12:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant