Skip to content

ci(deps): bump actions/setup-node from 4 to 7 - #727

Merged
enyst merged 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7
Oct 4, 2026
Merged

enyst merged 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps actions/setup-node from 4 to 7.

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 4, 2026
@github-actions github-actions Bot added the type: ci CI configuration changes label Oct 4, 2026

@all-hands-bot all-hands-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This review was posted by an AI agent (OpenHands).

Scope

In scope. This repository owns the GitHub Actions workflows it runs, and actions/setup-node is pinned in .github/workflows/*.yml. A dependency bump to one of those pins belongs here; no product/architecture decision is needed.

What the change does

Bumps actions/setup-node from @v4 to @v7 in .github/workflows/build-vscode-app.yml (line 15). The other three workflows (check-extensions.yml, npm-publish.yml, tests.yml) were already on @v7 on main, so this change brings the last workflow into line with the repo's existing convention - v7 is already proven in this repo's CI.

Checks for the exact head 76bf4fd...

  • package (the job that exercises this workflow's setup-node step): success.
  • test, check, sync-extensions, validate-claude-code, pr-title: success.
  • sync-sdk-skill: failure.

The sync-sdk-skill failure is not caused by this PR. It runs python scripts/sync_openhands_sdk_skill.py --check, which pulls live data from https://docs.openhands.dev/llms.txt and the OpenHands/software-agent-sdk repo, then compares the generated content against the committed skills/openhands-sdk/SKILL.md. I reproduced the identical failure locally on this head, and the last check-extensions.yml run on main (SHA 62f34e3, 2026-10-02) passed, so the drift appeared between that run and this PR's run. The failing job never reads setup-node or anything this PR touches; the diff is a single version string in an unrelated workflow file. It is a pre-existing/environmental failure that would block the PR through the required-check gate, not a defect introduced by the bump.

Findings

No material bugs, security problems, or design flaws in the change. actions/setup-node@v7 is a valid existing tag; the workflow still passes node-version: "20", and the packaging script (apps/vscode/scripts/package.mjs) uses standard node:* APIs unaffected by the action's ESM migration.

The only merge-blocking item is the unrelated sync-sdk-skill failure, which should be resolved by regenerating skills/openhands-sdk/SKILL.md on main (or rebasing this PR once main is green). That is outside this PR's diff.

✅ APPROVED

@all-hands-bot

Copy link
Copy Markdown
Contributor

🤖 OpenHands is fixing the failing CI on this dependabot version bump.

Head commit: 76bf4fd90e0a5060273896bb4e7644313cf7c6ea
View the conversation: https://oss-agent-canvas-backup.ngrok.dev/conversations/201ca1f1-2b71-4082-9c5f-b2dda57c5716

This comment was posted by an AI agent (OpenHands).

@enyst

enyst commented Oct 4, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@all-hands-bot all-hands-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This review was posted by an AI agent (OpenHands).

Scope

In scope. This repository owns the GitHub Actions workflows it runs, and actions/setup-node is pinned in .github/workflows/*.yml. A dependency bump to that pin belongs here; no product/architecture decision is needed.

What this head contains

The head b0bc414 is not just the dependabot bump. It carries two commits: the original 76bf4fd (actions/setup-node@v4 -> @v7 in build-vscode-app.yml) plus b0bc414 (fix(skills): make SDK skill sync resilient to llms.txt format change), which rewrites parse_sdk_entries in scripts/sync_openhands_sdk_skill.py and regenerates skills/openhands-sdk/SKILL.md and skills/index.js (+113/-61, 4 files). The setup-node bump itself is fine: v7 is already used by the other three workflows on main, the workflow still pins node-version: "20", and the package job that exercises this step passes.

Blocking issue: the branch now conflicts with main, which already contains an equivalent fix

main has advanced from this PR's base 62f34e3 to 15250b8 and independently fixed the exact same problem. PR #725 (ci(deps): bump actions/upload-artifact from 4 to 7, merged 2026-10-04T14:02:14Z, commit 3450e1a) already made scripts/sync_openhands_sdk_skill.py resilient to the dropped llms.txt heading by selecting entries via the https://docs.openhands.dev/sdk/ URL prefix, and it regenerated skills/openhands-sdk/SKILL.md. sync-sdk-skill passes on main's head 15250b8.

This PR reimplements the same fix a second way (heading-or-URL fallback instead of pure URL selection, without main's title sort) and regenerates a divergent skill. On this head the Guides section lists 102 entries versus 62 on main: the PR additionally emits 40 sdk/guides/agent-server/api-reference/... server endpoints (Alive, Health, Ready, Send Message, Get Skills, etc.) as Guides, because its _SDK_API_REF_RE only matches /sdk/api-reference/ and not the nested agent-server/api-reference paths that main excludes.

As a result the PR can no longer merge: GitHub reports mergeable: false, mergeable_state: dirty, rebaseable: false, and git merge-tree between main and this head reports content conflicts in scripts/sync_openhands_sdk_skill.py, skills/index.js, and skills/openhands-sdk/SKILL.md. The green checks on b0bc414 were produced against the old base 62f34e3, so they do not reflect the current merge result.

Recommendation

Rebase onto current main and drop the b0bc414 commit (or resolve the conflict by taking main's script and regenerating SKILL.md/index.js from it), keeping only the actions/setup-node@v7 bump. Note Dependabot cannot rebase this branch itself because it was edited by someone other than Dependabot; use @dependabot recreate or rebase manually.

Checks for this head

package, test, check, sync-extensions, sync-sdk-skill, validate-claude-code, and the pr-title jobs all completed successfully on b0bc414. The full workspace test suite also passes locally (1137 passed, 23 skipped) and sync_extensions.py --check is clean, but none of that clears the conflict with main above.

🔄 CHANGES REQUESTED

@enyst

enyst commented Oct 4, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/setup-node-7 branch from b0bc414 to 5a6957a Compare October 4, 2026 17:13
@enyst
enyst merged commit 8a7bab9 into main Oct 4, 2026
15 checks passed
@enyst
enyst deleted the dependabot/github_actions/actions/setup-node-7 branch October 4, 2026 17:25
@openhands-release-bot openhands-release-bot Bot added the released: v0.28.0 Shipped in v0.28.0 label Oct 5, 2026
@openhands-release-bot

Copy link
Copy Markdown
Contributor

🚀 Released in v0.28.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code released: v0.28.0 Shipped in v0.28.0 type: ci CI configuration changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants