ci(deps): bump actions/setup-node from 4 to 7 - #727
Conversation
all-hands-bot
left a comment
There was a problem hiding this comment.
This review was posted by an AI agent (OpenHands).
Scope
In scope. This repository owns the GitHub Actions workflows it runs, and actions/setup-node is pinned in .github/workflows/*.yml. A dependency bump to one of those pins belongs here; no product/architecture decision is needed.
What the change does
Bumps actions/setup-node from @v4 to @v7 in .github/workflows/build-vscode-app.yml (line 15). The other three workflows (check-extensions.yml, npm-publish.yml, tests.yml) were already on @v7 on main, so this change brings the last workflow into line with the repo's existing convention - v7 is already proven in this repo's CI.
Checks for the exact head 76bf4fd...
package(the job that exercises this workflow'ssetup-nodestep): success.test,check,sync-extensions,validate-claude-code,pr-title: success.sync-sdk-skill: failure.
The sync-sdk-skill failure is not caused by this PR. It runs python scripts/sync_openhands_sdk_skill.py --check, which pulls live data from https://docs.openhands.dev/llms.txt and the OpenHands/software-agent-sdk repo, then compares the generated content against the committed skills/openhands-sdk/SKILL.md. I reproduced the identical failure locally on this head, and the last check-extensions.yml run on main (SHA 62f34e3, 2026-10-02) passed, so the drift appeared between that run and this PR's run. The failing job never reads setup-node or anything this PR touches; the diff is a single version string in an unrelated workflow file. It is a pre-existing/environmental failure that would block the PR through the required-check gate, not a defect introduced by the bump.
Findings
No material bugs, security problems, or design flaws in the change. actions/setup-node@v7 is a valid existing tag; the workflow still passes node-version: "20", and the packaging script (apps/vscode/scripts/package.mjs) uses standard node:* APIs unaffected by the action's ESM migration.
The only merge-blocking item is the unrelated sync-sdk-skill failure, which should be resolved by regenerating skills/openhands-sdk/SKILL.md on main (or rebasing this PR once main is green). That is outside this PR's diff.
✅ APPROVED
|
🤖 OpenHands is fixing the failing CI on this dependabot version bump. Head commit: This comment was posted by an AI agent (OpenHands). |
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
all-hands-bot
left a comment
There was a problem hiding this comment.
This review was posted by an AI agent (OpenHands).
Scope
In scope. This repository owns the GitHub Actions workflows it runs, and actions/setup-node is pinned in .github/workflows/*.yml. A dependency bump to that pin belongs here; no product/architecture decision is needed.
What this head contains
The head b0bc414 is not just the dependabot bump. It carries two commits: the original 76bf4fd (actions/setup-node@v4 -> @v7 in build-vscode-app.yml) plus b0bc414 (fix(skills): make SDK skill sync resilient to llms.txt format change), which rewrites parse_sdk_entries in scripts/sync_openhands_sdk_skill.py and regenerates skills/openhands-sdk/SKILL.md and skills/index.js (+113/-61, 4 files). The setup-node bump itself is fine: v7 is already used by the other three workflows on main, the workflow still pins node-version: "20", and the package job that exercises this step passes.
Blocking issue: the branch now conflicts with main, which already contains an equivalent fix
main has advanced from this PR's base 62f34e3 to 15250b8 and independently fixed the exact same problem. PR #725 (ci(deps): bump actions/upload-artifact from 4 to 7, merged 2026-10-04T14:02:14Z, commit 3450e1a) already made scripts/sync_openhands_sdk_skill.py resilient to the dropped llms.txt heading by selecting entries via the https://docs.openhands.dev/sdk/ URL prefix, and it regenerated skills/openhands-sdk/SKILL.md. sync-sdk-skill passes on main's head 15250b8.
This PR reimplements the same fix a second way (heading-or-URL fallback instead of pure URL selection, without main's title sort) and regenerates a divergent skill. On this head the Guides section lists 102 entries versus 62 on main: the PR additionally emits 40 sdk/guides/agent-server/api-reference/... server endpoints (Alive, Health, Ready, Send Message, Get Skills, etc.) as Guides, because its _SDK_API_REF_RE only matches /sdk/api-reference/ and not the nested agent-server/api-reference paths that main excludes.
As a result the PR can no longer merge: GitHub reports mergeable: false, mergeable_state: dirty, rebaseable: false, and git merge-tree between main and this head reports content conflicts in scripts/sync_openhands_sdk_skill.py, skills/index.js, and skills/openhands-sdk/SKILL.md. The green checks on b0bc414 were produced against the old base 62f34e3, so they do not reflect the current merge result.
Recommendation
Rebase onto current main and drop the b0bc414 commit (or resolve the conflict by taking main's script and regenerating SKILL.md/index.js from it), keeping only the actions/setup-node@v7 bump. Note Dependabot cannot rebase this branch itself because it was edited by someone other than Dependabot; use @dependabot recreate or rebase manually.
Checks for this head
package, test, check, sync-extensions, sync-sdk-skill, validate-claude-code, and the pr-title jobs all completed successfully on b0bc414. The full workspace test suite also passes locally (1137 passed, 23 skipped) and sync_extensions.py --check is clean, but none of that clears the conflict with main above.
🔄 CHANGES REQUESTED
|
@dependabot recreate |
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4...v7) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
b0bc414 to
5a6957a
Compare
|
🚀 Released in v0.28.0. |
Bumps actions/setup-node from 4 to 7.
Release notes
Sourced from actions/setup-node's releases.
... (truncated)
Commits
8207627Migrate to ESM and upgrade dependencies (#1574)04be95cAdd cache-primary-key and cache-matched-key as outputs (#1577)7c2c68ddocs: Update caching recommendations to mitigate cache poisoning risks (#1567)6a61c03Merge pull request #1569 from jasongin/update-actions-cache-5.1.030eb73bResolve high-severity audit issues4e1a87aUpdate dist360237fStrict equality4f8aac5Bump@actions/cacheto 5.1.0, log cache write deniedf4a67bbOnly usemirrorTokeningetManifestif it's provided (#1548)0355742Remove dummy NODE_AUTH_TOKEN export (#1558)