chore: migrate to Node 24 runtime (v3) - #215
Merged
Merged
Conversation
- Update action.yml from node20 to node24 - Bump @actions/core from 1.10.0 to 1.11.1 - Rebuild dist/ bundle - Update example.yml: checkout@v3 -> @v6, gitleaks-action@v2 -> @V3 - Update gitleaks-action-HEAD.yml: checkout@v4 -> @v6 - Add v2 -> v3 migration guide to README GitHub is deprecating Node 20 for Actions on June 2, 2026 (opt-out required) with full removal on September 16, 2026. This is a breaking change released as v3.0.0 to give users explicit control over the upgrade. Co-authored-by: Cursor <cursoragent@cursor.com>
bryanbeverly
force-pushed
the
chore/node24-v3
branch
from
May 5, 2026 18:59
8f25db5 to
bb773fe
Compare
1 task done
2 of 5 tasks
Twodragon0
added a commit
to Twodragon0/claudesec
that referenced
this pull request
May 21, 2026
Audit of every SHA-pinned action in .github/workflows/ found one real node20 user left after #157 bumped dependency-review-action to v5.0.0: gitleaks/gitleaks-action@ff98106e (v2.3.9, latest). The upstream node24 migration is in flight (gitleaks/gitleaks-action#215, still open as of 2026-05-19), so waiting for a tagged release would risk missing the GitHub deadline. Replace the action wrapper with a direct gitleaks CLI install plus `gitleaks dir` scan against the working tree. CLI binary is pinned to v8.30.1 with sha256 verification against the published checksums file. This preserves the secret-scan layer while removing the node20 dependency. PR-comment functionality is already covered by the local pre-commit gitleaks hook and the separate GitGuardian Security Checks service. Also cleans up two stale workflow comments uncovered during the audit: - `actions/dependency-review-action` is now v5.0.0 (node24) — the "still uses node20" NOTE at the call site is outdated post-#157. - `ludeeus/action-shellcheck@00cae500` is a composite action (no node runtime), so it was never affected by the node20 deprecation; the previous NOTE misclassified it. Audit summary of the 12 other SHA-pinned actions: all on `node24` or `composite` runtimes, no further action needed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Twodragon0
added a commit
to Twodragon0/claudesec
that referenced
this pull request
May 21, 2026
Audit of every SHA-pinned action in .github/workflows/ found one real node20 user left after #157 bumped dependency-review-action to v5.0.0: gitleaks/gitleaks-action@ff98106e (v2.3.9, latest). The upstream node24 migration is in flight (gitleaks/gitleaks-action#215, still open as of 2026-05-19), so waiting for a tagged release would risk missing the GitHub deadline. Replace the action wrapper with a direct gitleaks CLI install plus `gitleaks dir` scan against the working tree. CLI binary is pinned to v8.30.1 with sha256 verification against the published checksums file. This preserves the secret-scan layer while removing the node20 dependency. PR-comment functionality is already covered by the local pre-commit gitleaks hook and the separate GitGuardian Security Checks service. Also cleans up two stale workflow comments uncovered during the audit: - `actions/dependency-review-action` is now v5.0.0 (node24) — the "still uses node20" NOTE at the call site is outdated post-#157. - `ludeeus/action-shellcheck@00cae500` is a composite action (no node runtime), so it was never affected by the node20 deprecation; the previous NOTE misclassified it. Audit summary of the 12 other SHA-pinned actions: all on `node24` or `composite` runtimes, no further action needed. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2 of 4 tasks
This was referenced May 30, 2026
This was referenced Jul 16, 2026
This was referenced Jul 30, 2026
This was referenced Aug 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Migrates
gitleaks-actionfrom the Node 20 GitHub Actions runtime to Node 24, released as v3.0.0.action.yml:using: "node20"->using: "node24"@actions/corebumped from1.10.0to1.11.1for Node 24 compatibilitydist/index.jsrebuilt vianccactions/checkout@v3/@v4->@v6,gitleaks-action@v2->@v3README.mdupdated with v3 migration guide and Node 20 deprecation timelineWhy v3 (major bump)?
Node 24 requires runner v2.327.1+. Self-hosted runner operators who haven't updated would break silently if we shipped this under the existing
@v2tag. A major version bump gives all consumers explicit opt-in.Node 20 deprecation timeline
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=trueto keep running.gitleaks-action@v2stops working entirely.After merge
v3.0.0and create a GitHub Release with migration notesv3tag pointing to the same commitgitleaks/gitleaks,gitleaks/.github,gitleaks/website) to reference@v3Test plan
gitleaks-action-HEAD.ymlworkflow tests the action from./, confirming it runs on Node 24)dist/index.jsbundle is correct (rebuilt withnpx ncc build src/index.js -o dist)gitleaks/gitleaks-action@v3runs successfullyMade with Cursor