Skip to content

SRE-3632: Bypass node check to allow time for upstream actions update - #36

Merged
dontiveros-tatari merged 1 commit into
mainfrom
SRE-3632/add_node_version_override
May 26, 2026
Merged

dontiveros-tatari merged 1 commit into
mainfrom
SRE-3632/add_node_version_override

Conversation

@dontiveros-tatari

Copy link
Copy Markdown
Contributor

Summary

Adds ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: "true" to the gitleaks/gitleaks-action step in security.yaml. This env var is scoped to that step only and has no impact on actions/checkout which is already on node24.

Why

GitHub is forcing all actions to run on Node.js 24 by default starting June 2nd, 2026. gitleaks/gitleaks-action@ff98106 (v2.3.9) is still on node20. The upstream node24 migration PR (gitleaks/gitleaks-action#215) has been open since May 5 with no reviews and no release in sight.

Since security.yaml runs as a required workflow across 45 repos, a single central fix is the only way to address all instances before the deadline. ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION is GitHub's documented opt-out mechanism as stated in their own deprecation notice.

Validation

Code search across all 472 tatari-tv repos confirmed gitleaks/gitleaks-action is only referenced in this file — no per-repo usages exist. This PR is the complete fix for all 45 affected repos.

Test plan

  1. Merge this PR
  2. Open a test PR on any affected repo (e.g. conductor)
  3. Check the Required Workflows Security job annotations
  4. Confirm Node.js 20 deprecation warning is no longer present
  5. Confirm gitleaks scan still runs and completes successfully

🤖 Planned with Claude Code

@dontiveros-tatari
dontiveros-tatari requested a review from a team as a code owner May 26, 2026 17:54
@coderabbitai

coderabbitai Bot commented May 26, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The security workflow is updated to set ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true in the environment of the gitleaks action step, allowing the scan job to proceed with an unsecure Node version.

Changes

Gitleaks Action Configuration

Layer / File(s) Summary
Gitleaks action environment configuration
.github/workflows/security.yaml
The gitleaks/gitleaks-action step environment is extended with ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true to permit unsecure Node version usage.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically describes the main change: adding a Node.js version check bypass to allow time for an upstream action update, directly matching the changeset.
Description check ✅ Passed The description is directly related to the changeset, explaining the environment variable addition, the reason for the change, validation approach, and test plan with specific context.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch SRE-3632/add_node_version_override
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch SRE-3632/add_node_version_override

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/security.yaml:
- Line 33: Add a sunset TODO comment above the
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true override noting the owner and a
target removal date (e.g., "TODO(owner@example.com): remove when
gitleaks/gitleaks-action supports Node 24 by YYYY-MM-DD"); reference the
override key ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION and the pinned action
gitleaks/gitleaks-action@v2.3.9 so it's clear this is a temporary bypass for
Node 20/24 compatibility and should be removed once an upstream release
supporting Node 24 is adopted.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 180ce5ce-fb13-407b-bb1b-6218eb1897bd

📥 Commits

Reviewing files that changed from the base of the PR and between 471ea59 and 9018150.

📒 Files selected for processing (1)
  • .github/workflows/security.yaml

env:
GITHUB_TOKEN: ${{secrets.GITHUB_TOKEN}}
GITLEAKS_LICENSE: ${{secrets.GITLEAKS_LICENSE}}
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🌐 Web query:

What is the latest gitleaks/gitleaks-action release, and does its action.yml set runs.using to node24?

💡 Result:

Latest gitleaks/gitleaks-action release: v2.3.9 (published 2025-04-17) [1]. Does its action.yml set runs.using to node24? No—on the repo’s current action.yml (master), the metadata sets runs.using: "node20" [2]. Note: there is evidence of a separate change request/migration to Node 24 in the gitleaks/gitleaks-action repo (PR titled “migrate to Node 24 runtime (v3)”) [3], but the action.yml we found sets node20 [2].

Citations:


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/security.yaml"

echo "== File = $FILE =="
echo "--- Lines 1-120 ---"
nl -ba "$FILE" | sed -n '1,120p'

echo "--- Lines around 33 ---"
nl -ba "$FILE" | sed -n '25,45p'

Repository: tatari-tv/github-required-workflows

Length of output: 205


🏁 Script executed:

#!/bin/bash
set -euo pipefail

FILE=".github/workflows/security.yaml"
echo "== Exists? =="
test -f "$FILE" && echo "yes" || (echo "no"; exit 1)

echo "== Line count =="
wc -l "$FILE"

echo "--- Lines 25-45 ---"
cat -n "$FILE" | sed -n '25,45p'

echo "--- Grep for ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION ---"
rg -n "ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION" "$FILE" || true

Repository: tatari-tv/github-required-workflows

Length of output: 827


Add a sunset marker for the temporary Node runtime bypass
Line 33 sets ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true while the pinned gitleaks/gitleaks-action@v2.3.9 is configured to run on Node 20, so this override can silently persist—add a TODO with an explicit owner/date to remove once the upstream action release that supports Node 24 is adopted.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/security.yaml at line 33, Add a sunset TODO comment above
the ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true override noting the owner and
a target removal date (e.g., "TODO(owner@example.com): remove when
gitleaks/gitleaks-action supports Node 24 by YYYY-MM-DD"); reference the
override key ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION and the pinned action
gitleaks/gitleaks-action@v2.3.9 so it's clear this is a temporary bypass for
Node 20/24 compatibility and should be removed once an upstream release
supporting Node 24 is adopted.

@dontiveros-tatari
dontiveros-tatari merged commit fee62e3 into main May 26, 2026
3 checks passed
@dontiveros-tatari
dontiveros-tatari deleted the SRE-3632/add_node_version_override branch May 26, 2026 18:36
@tatari-deployments

tatari-deployments Bot commented May 26, 2026 •

Copy link
Copy Markdown

🙏 This merge started its CI workflow on Main with GitHub Actions 🖥️

👍 This merge completed its CI workflow on Main with GitHub Actions 🖥️

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants