chore(ci): clear remaining node20 path before 2026-06-02 deadline - #163
Merged
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
This PR updates the CI lint workflow to remove the last remaining Node 20–based GitHub Action usage ahead of the 2026-06-02 deprecation by replacing gitleaks/gitleaks-action with a pinned, checksum-verified Gitleaks CLI install and scan. It also corrects stale/inaccurate workflow comments discovered during the audit.
Changes:
- Replace
gitleaks/gitleaks-action(node20) with direct Gitleaks CLI download (v8.30.1) +gitleaks dirscan. - Update workflow comments for
actions/dependency-review-action(now node24) and clarifyludeeus/action-shellcheckis composite (no node runtime).
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+365
to
+367
| GITLEAKS_VERSION: "8.30.1" | ||
| # https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_checksums.txt | ||
| GITLEAKS_SHA256: "551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb" |
Audit of every SHA-pinned action in .github/workflows/ found one real node20 user left after #157 bumped dependency-review-action to v5.0.0: gitleaks/gitleaks-action@ff98106e (v2.3.9, latest). The upstream node24 migration is in flight (gitleaks/gitleaks-action#215, still open as of 2026-05-19), so waiting for a tagged release would risk missing the GitHub deadline. Replace the action wrapper with a direct gitleaks CLI install plus `gitleaks dir` scan against the working tree. CLI binary is pinned to v8.30.1 with sha256 verification against the published checksums file. This preserves the secret-scan layer while removing the node20 dependency. PR-comment functionality is already covered by the local pre-commit gitleaks hook and the separate GitGuardian Security Checks service. Also cleans up two stale workflow comments uncovered during the audit: - `actions/dependency-review-action` is now v5.0.0 (node24) — the "still uses node20" NOTE at the call site is outdated post-#157. - `ludeeus/action-shellcheck@00cae500` is a composite action (no node runtime), so it was never affected by the node20 deprecation; the previous NOTE misclassified it. Audit summary of the 12 other SHA-pinned actions: all on `node24` or `composite` runtimes, no further action needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Twodragon0
force-pushed
the
chore/node20-cleanup-gitleaks-cli
branch
from
May 21, 2026 03:36
125dc2d to
c236fb7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Audit of every SHA-pinned action in
.github/workflows/lint.yml(12 actions in total) found exactly one real node20 user remaining after #157 bumpedactions/dependency-review-actionto v5.0.0:gitleaks/gitleaks-action@ff98106e(v2.3.9, latest available).The upstream node24 migration is in flight (gitleaks-action#215, still open as of 2026-05-19) so waiting for a tagged release risks missing the 2026-06-02 GitHub deprecation deadline (D-12).
This PR:
gitleaks/gitleaks-action@v2.3.9with a directgitleaksCLI install (pinned to v8.30.1, sha256 verified against published checksums) +gitleaks dirscan against the working tree. Same security gate, no node20 dependency.actions/dependency-review-actionis on v5.0.0 (node24) since chore(deps): bump the actions group across 1 directory with 4 updates #157 — the "still uses node20" NOTE at the call site is outdated.ludeeus/action-shellcheck@00cae500is a composite action (no node runtime), so it was never affected by the deprecation; the previous NOTE misclassified it.Audit table
actions/checkoutde0fac2e(v6)actions/setup-pythona309ff8bactions/upload-artifact043fb46d(v7)actions/download-artifact3e5f45b2(v8)actions/dependency-review-actiona1d282b3(v5.0.0)codecov/codecov-actione79a6962(v6.0.1)dependabot/fetch-metadata25dd0e34(v3.1.0)lycheeverse/lychee-action8646ba30mikepenz/action-junit-report3a81627b(v6.4.1)treosh/lighthouse-ci-action3e7e23fb(v12.6.2)DavidAnson/markdownlint-cli2-actionded1f948(v23)docker/build-push-actionbcafcacbdocker/setup-buildx-action4d04d5d9ludeeus/action-shellcheck00cae500gitleaks/gitleaks-actionff98106e(v2.3.9)Why CLI replacement is safe
gitleaks dir .(the v8.20+ replacement for legacydetect --no-git) scans the working tree, which is exactly whatgitleaks-actionwas effectively doing for PR/push events.https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_checksums.txt.Test plan
python3 -c "import yaml; yaml.safe_load(...)")gitleaks dir . --config .gitleaks.toml --redact --no-banner --exit-code 1against working tree → exit 0gitleaksjob green on this PR with the new CLI invocationFollow-up
When
gitleaks/gitleaks-action#215is tagged on node24, we can optionally migrate back to get the PR-comment feature. Not urgent.🤖 Generated with Claude Code