Skip to content

Update softprops/action-gh-release action to v3 - #4057

Merged
amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/softprops-action-gh-release-3.x
Jul 9, 2026
Merged

amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/softprops-action-gh-release-3.x

Conversation

@amitsingh-007

@amitsingh-007 amitsingh-007 commented Jul 8, 2026 •

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Type Update Change
softprops/action-gh-release action major v2 → v3

Release Notes

softprops/action-gh-release (softprops/action-gh-release)

v3.0.1

Compare Source

3.0.1

  • maintenance release with updated dependencies

v3.0.0

Compare Source

3.0.0 is a major release that moves the action runtime from Node 20 to Node 24.
Use v3 on GitHub-hosted runners and self-hosted fleets that already support the
Node 24 Actions runtime. If you still need the last Node 20-compatible line, stay on
v2.6.2.

What's Changed

Other Changes 🔄
  • Move the action runtime and bundle target to Node 24
  • Update @types/node to the Node 24 line and allow future Dependabot updates
  • Keep the floating major tag on v3; v2 remains pinned to the latest 2.x release

v3

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

Greptile Summary

This PR upgrades softprops/action-gh-release from v2 to v3 in the release workflow. The only change is a single line in .github/workflows/release.yml.

  • The v3 major release moves the action runtime from Node 20 to Node 24; no input/output interface changes are documented, so the existing with: configuration (name, tag_name, token, generate_release_notes, files) remains compatible.

Confidence Score: 5/5

Safe to merge — a one-line runtime upgrade with no interface changes.

The change is a single-line bump of a GitHub Action from Node 20 to Node 24. The action's public interface (inputs and outputs) is unchanged between v2 and v3, so the existing workflow configuration will continue to work without modification.

No files require special attention.

Reviews (1): Last reviewed commit: "Update softprops/action-gh-release actio..." | Re-trigger Greptile

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Bump softprops/action-gh-release to v3 in release workflow

⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Upgrade softprops/action-gh-release from v2 to v3 in release workflow.
• Align release publishing step with upstream Node 24 Actions runtime requirement.
Diagram

graph TD
  A[".github/workflows/release.yml"] --> B["Create_Release job"] --> C["softprops/action-gh-release@v3"] --> D["GitHub Releases"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Pin to a specific v3 patch (e.g., v3.0.1)
  • ➕ Maximizes reproducibility; avoids unexpected behavior changes from new v3 patch releases
  • ➖ Misses automatic patch updates unless manually bumped/renovated
2. Stay on v2.6.2 (Node 20 runtime)
  • ➕ Maintains compatibility with older/self-hosted runners that don’t support the Node 24 Actions runtime
  • ➖ Does not move to the new major line; may lag behind future maintenance/security updates targeting v3

Recommendation: Proceed with v3 if all target runners (including any self-hosted fleets) support the Node 24 Actions runtime. If you want tighter supply-chain/reproducibility guarantees for releases, consider pinning to v3.0.1 instead of the floating v3 tag; otherwise, floating v3 is reasonable to pick up maintenance patch updates automatically.

Files changed (1) +1 / -1

Other (1) +1 / -1
release.ymlUpdate release action to softprops/action-gh-release@v3 +1/-1

Update release action to softprops/action-gh-release@v3

• Updates the Create Release step to use softprops/action-gh-release v3 instead of v2. This moves the workflow onto the action’s Node 24 runtime line as required by the upstream major release.

.github/workflows/release.yml

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (0) 📜 Skill insights (0)

Context used
✅ Compliance rules (platform): 22 rules

Grey Divider


Informational

1. Unpinned release action 🐞 Bug ⛨ Security
Description
The release workflow uses a floating tag (softprops/action-gh-release@v3) for a step that can
publish GitHub releases, so future tag retargeting or an upstream compromise could cause unintended
code to run with the workflow’s GitHub token context.
Code

.github/workflows/release.yml[196]

+        uses: softprops/action-gh-release@v3
Relevance

⭐ Low

Repo workflows routinely use floating action tags (e.g., vercel-action@v42,
renovatebot/github-action@v46.1.18); no SHA-pinning precedent.

PR-#3991
PR-#4009

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The workflow’s release publishing step is executed from a floating @v3 tag and is passed
secrets.GITHUB_TOKEN, so the action’s code is not immutably pinned while running in a privileged
release context.

.github/workflows/release.yml[195-203]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The workflow runs `softprops/action-gh-release` from a mutable tag (`@v3`). Because this step publishes releases and is provided a GitHub token, pinning to an immutable commit SHA reduces supply-chain risk.

### Issue Context
This is the release creation step in `.github/workflows/release.yml`.

### Fix Focus Areas
- .github/workflows/release.yml[195-201]

### Suggested change
- Replace `uses: softprops/action-gh-release@v3` with `uses: softprops/action-gh-release@<full_commit_sha>`.
- (Optional) Add an inline comment like `# v3.0.1` to keep the intended version readable, and let Renovate update the SHA in future PRs.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@amitsingh-007
amitsingh-007 merged commit f35cdf0 into renovate-updates Jul 9, 2026
2 checks passed
@amitsingh-007
amitsingh-007 deleted the renovate/softprops-action-gh-release-3.x branch July 9, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant