Skip to content

ci: update GitHub Actions to latest versions - #2

Open
czprz wants to merge 2 commits into
mainfrom
ci/update-github-actions
Open

czprz wants to merge 2 commits into
mainfrom
ci/update-github-actions

Conversation

@czprz

@czprz czprz commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Summary

Updates GitHub Actions used in CI/release workflows to their latest versions and aligns pinning strategy.

ci.yml (SHA-pinned, version bumped)

  • actions/checkout -> v7.0.1
  • actions/setup-go -> v7.0.0
  • golangci-lint-action -> v9.3.0

release.yml (converted from floating tags to SHA-pinning, for consistency with ci.yml)

  • actions/checkout v4 -> v7.0.1
  • actions/setup-go v5 -> v7.0.0
  • actions/upload-artifact v4 -> v7.0.1
  • actions/download-artifact v4 -> v8.0.1
  • softprops/action-gh-release v2 -> v3.0.3

Testing

  • Validated YAML syntax of both workflow files with js-yaml.
  • Ran go build ./... and go vet ./... locally - no impact on Go code, build passes.

czprz and others added 2 commits September 27, 2026 22:08
- actions/checkout v6 -> v7.0.1
- actions/setup-go v6.4.0 -> v7.0.0
- golangci-lint-action v9.2.x -> v9.3.0
- actions/upload-artifact v4 -> v7.0.1
- actions/download-artifact v4 -> v8.0.1
- softprops/action-gh-release v2 -> v3.0.3

Also re-pinned release.yml actions to commit SHAs (with version
comments) for consistency with ci.yml's existing SHA-pinning
security practice.

Co-authored-by: Copilot <[email protected]>
alpine:3.19 -> alpine:3.24 (latest stable)

Co-authored-by: Copilot <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant