You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Upgrades actions/checkout from @v4 to @v7.0.1 (pinned to its immutable
commit SHA 3d3c42e5aac5ba805825da76410c181273ba90b1, matching the pattern
already used in .github/workflows/repo-assist.lock.yml and .github/workflows/copilot-setup-steps.yml) across the three checkout steps
in .github/workflows/ci.yml (lint, test-pwsh, test-powershell jobs).
Root cause
actions/checkout@v4 targets the deprecated Node.js 20 runtime. GitHub will
remove Node.js 20 from Actions runners on September 23, 2026, after which
runs relying on the current compatibility shim will fail. actions/checkout@v7
natively targets Node.js 24.
Changes
.github/workflows/ci.yml (lines 18, 55, 107): replaced actions/checkout@v4 with the pinned actions/[email protected] SHA.
Limitations
.github/workflows/publish.yml (line 18) was intentionally left
unchanged. This automation's operating rules prohibit modifying release
or PowerShell Gallery publishing workflows. A maintainer will need to
apply the same actions/checkout@v7 upgrade to publish.yml separately
to fully close Upgrade GitHub workflows to actions/checkout v7 #85's checklist.
This is a CI-workflow-only change; no PowerShell module code was touched.
Pester (Invoke-Pester ./Tests/AzRetirementMonitor.Tests.ps1) could not be
run in this sandbox because PSGallery/module installation requires
network access to the PowerShell Gallery, which isn't available here.
Since no .ps1/.psm1 files were modified, no regression in module
behavior is expected, but the actual CI run on this PR (ubuntu-latest,
windows-latest, macos-latest, and Windows PowerShell 5.1 job) will provide
the real validation of the new checkout action across all matrix jobs.
Test results
Local Pester run: not executable in this sandbox (no PSGallery network
access). No module code changed by this PR.
Will be validated by the CI workflow itself once this PR runs.
Left as a draft for maintainer review, per Repo Assist policy.
Warning
Protected Files — Push Permission Denied
This was originally intended as a pull request, but the change modifies protected files. A human must create the pull request manually.
The push was rejected because GitHub Actions does not have workflows permission to push these changes, and is never allowed to make such changes, or other authorization being used does not have this permission.
Create the pull request manually
# Download the artifact from the workflow run
gh run download '34865109413' -n agent -D '/tmp/agent-34865109413'# Resolve the bundle source ref, fetch it into a temporary ref, then create the local branch
bundle_path='/tmp/agent-34865109413/aw-feature-issue-85-checkout-v7.bundle'
temp_ref='refs/bundles/create-pr-feature-issue-85-checkout-v7-fef59b5fab82fedc-b35bf0fe'
target_ref='refs/heads/feature/issue-85-checkout-v7-fef59b5fab82fedc'
bundle_source_ref=$(git bundle list-heads "$bundle_path"| awk '$2 ~ /^refs\/heads\// { print $2 }')if [ -z"$bundle_source_ref" ];then
bundle_source_ref=$(git bundle list-heads "$bundle_path"| awk '$2 == "HEAD" { print $2 }')fiif [ "$(printf '%s\n'"$bundle_source_ref"| sed '/^$/d'| wc -l | tr -d '')"!="1" ];thenecho"Expected exactly one bundle source ref, found: $bundle_source_ref">&2exit 1
fi
git fetch "$bundle_path""${bundle_source_ref}:${temp_ref}"
git update-ref "$target_ref""$temp_ref"
git checkout 'feature/issue-85-checkout-v7-fef59b5fab82fedc'# Ensure the working tree matches the updated branch
git reset --hard
# Remove the temporary bundle ref
git update-ref -d "$temp_ref"# Push the branch and create the pull request
git push origin feature/issue-85-checkout-v7-fef59b5fab82fedc
gh pr create --title '[Repo Assist] ci: upgrade actions/checkout to v7 in CI workflow' --base main --head feature/issue-85-checkout-v7-fef59b5fab82fedc --repo cocallaw/AzRetirementMonitor
Generated by AzRetirementMonitor Repo Assist · copilot · auto · 41.5 AIC · ⌖ 9.26 AIC · ⊞ 8.9K · ◷ Comment /repo-assist to run again
🤖 This draft PR was created by an automated assistant (Repo Assist).
Summary
Closes #85 (partially — see Limitations).
Upgrades
actions/checkoutfrom@v4to@v7.0.1(pinned to its immutablecommit SHA
3d3c42e5aac5ba805825da76410c181273ba90b1, matching the patternalready used in
.github/workflows/repo-assist.lock.ymland.github/workflows/copilot-setup-steps.yml) across the three checkout stepsin
.github/workflows/ci.yml(lint, test-pwsh, test-powershell jobs).Root cause
actions/checkout@v4targets the deprecated Node.js 20 runtime. GitHub willremove Node.js 20 from Actions runners on September 23, 2026, after which
runs relying on the current compatibility shim will fail.
actions/checkout@v7natively targets Node.js 24.
Changes
.github/workflows/ci.yml(lines 18, 55, 107): replacedactions/checkout@v4with the pinnedactions/[email protected]SHA.Limitations
.github/workflows/publish.yml(line 18) was intentionally leftunchanged. This automation's operating rules prohibit modifying release
or PowerShell Gallery publishing workflows. A maintainer will need to
apply the same
actions/checkout@v7upgrade topublish.ymlseparatelyto fully close Upgrade GitHub workflows to actions/checkout v7 #85's checklist.
Invoke-Pester ./Tests/AzRetirementMonitor.Tests.ps1) could not berun in this sandbox because
PSGallery/module installation requiresnetwork access to the PowerShell Gallery, which isn't available here.
Since no
.ps1/.psm1files were modified, no regression in modulebehavior is expected, but the actual CI run on this PR (ubuntu-latest,
windows-latest, macos-latest, and Windows PowerShell 5.1 job) will provide
the real validation of the new checkout action across all matrix jobs.
Test results
access). No module code changed by this PR.
Left as a draft for maintainer review, per Repo Assist policy.
Warning
Protected Files — Push Permission Denied
This was originally intended as a pull request, but the change modifies protected files. A human must create the pull request manually.
Protected files
The push was rejected because GitHub Actions does not have
workflowspermission to push these changes, and is never allowed to make such changes, or other authorization being used does not have this permission.Create the pull request manually