CenterForDigitalHumanities / CenterForDigitalHumanities/TPEN-services

CI/CD: pin GitHub Actions to @v4 instead of @master

Open
#525 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Description

## Summary

Our CI/CD workflows pin GitHub Actions to the moving `@master` branch instead of a stable major-version tag like `@v4`. This means every workflow run silently picks up whatever HEAD of `actions/checkout`, `actions/setup-node`, and `actions/cache` happens to be — there is no diff in this repo when those upstream branches change, so a green PR yesterday can fail today for reasons we cannot see.

## Affected workflows

All inherited from before the test-harness conversion (PR #524). Not introduced by recent work — long-standing drift.

- `.github/workflows/ci_dev.yaml` — 6 occurrences
- `.github/workflows/ci_prod.yaml` — 9 occurrences
- `.github/workflows/cd_dev.yaml` — 4 occurrences
- `.github/workflows/cd_prod.yaml` — 4 occurrences
- `.github/workflows/test_pushes.yaml` — 3 occurrences

Total: ~27 `@master` references across 5 workflows.

The new `.github/workflows/sync_tpen_shared_openapi.yaml` already pins `actions/checkout@v4` correctly, so the inconsistency exists internally too.

## Why this matters

- **Reproducibility** — same YAML produces different behavior over time.
- **Supply-chain surface** — a malicious or accidental commit to `actions/checkout`'s master branch propagates to every run immediately.
- **Breaking changes** — when `actions/checkout@v5` ships, `@master` consumers get the breakage at the next run with no warning.
- **GitHub's own guidance** explicitly recommends pinning to a major version tag or a SHA. Major-version tags (`@v4`) still receive patch/security updates automatically.

## Cross-repo alignment

- RERUM v1 (`CenterForDigitalHumanities/rerum_server_nodejs`) already uses `@v4` across all CI/CD workflows.
- TinyPEN (`CenterForDigitalHumanities/TinyPen`) has the same `@master` drift — tracked separately in a TinyPen issue.

## Proposed fix

Normalize all five workflows to:

- `actions/checkout@v4`
- `actions/setup-node@v4`
- `actions/cache@v4`

Single-PR sweep, no behavior changes expected (all three actions' `@v4` tag is the latest stable major and what RERUM v1 already runs on).

## Acceptance criteria

- [ ] No `@master` references remain in `.github/workflows/`.
- [ ] All `actions/checkout`, `actions/setup-node`, `actions/cache` references pin a major version tag (`@v4`).
- [ ] CI passes on the sweep PR (validates the pins are compatible with our Node 24 setup).

## Out of scope

- Pinning to commit SHAs — first-party `actions/*` major-version tags are sufficient.
- Migrating to a different Node setup action.
- TinyPEN cleanup — separate issue.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.