SRE-3632: Bypass node check to allow time for upstream actions update - #36
Conversation
📝 WalkthroughWalkthroughThe security workflow is updated to set ChangesGitleaks Action Configuration
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/security.yaml:
- Line 33: Add a sunset TODO comment above the
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true override noting the owner and a
target removal date (e.g., "TODO(owner@example.com): remove when
gitleaks/gitleaks-action supports Node 24 by YYYY-MM-DD"); reference the
override key ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION and the pinned action
gitleaks/gitleaks-action@v2.3.9 so it's clear this is a temporary bypass for
Node 20/24 compatibility and should be removed once an upstream release
supporting Node 24 is adopted.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Central YAML (base), Organization UI (inherited)
Review profile: CHILL
Plan: Pro
Run ID: 180ce5ce-fb13-407b-bb1b-6218eb1897bd
📒 Files selected for processing (1)
.github/workflows/security.yaml
| env: | ||
| GITHUB_TOKEN: ${{secrets.GITHUB_TOKEN}} | ||
| GITLEAKS_LICENSE: ${{secrets.GITLEAKS_LICENSE}} | ||
| ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true |
There was a problem hiding this comment.
🧩 Analysis chain
🌐 Web query:
What is the latest gitleaks/gitleaks-action release, and does its action.yml set runs.using to node24?
💡 Result:
Latest gitleaks/gitleaks-action release: v2.3.9 (published 2025-04-17) [1]. Does its action.yml set runs.using to node24? No—on the repo’s current action.yml (master), the metadata sets runs.using: "node20" [2]. Note: there is evidence of a separate change request/migration to Node 24 in the gitleaks/gitleaks-action repo (PR titled “migrate to Node 24 runtime (v3)”) [3], but the action.yml we found sets node20 [2].
Citations:
- 1: https://github.com/gitleaks/gitleaks-action/releases/tag/v2.3.9
- 2: https://github.com/gitleaks/gitleaks-action/blob/master/action.yml
- 3: chore: migrate to Node 24 runtime (v3) gitleaks/gitleaks-action#215
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/security.yaml"
echo "== File = $FILE =="
echo "--- Lines 1-120 ---"
nl -ba "$FILE" | sed -n '1,120p'
echo "--- Lines around 33 ---"
nl -ba "$FILE" | sed -n '25,45p'Repository: tatari-tv/github-required-workflows
Length of output: 205
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/security.yaml"
echo "== Exists? =="
test -f "$FILE" && echo "yes" || (echo "no"; exit 1)
echo "== Line count =="
wc -l "$FILE"
echo "--- Lines 25-45 ---"
cat -n "$FILE" | sed -n '25,45p'
echo "--- Grep for ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION ---"
rg -n "ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION" "$FILE" || trueRepository: tatari-tv/github-required-workflows
Length of output: 827
Add a sunset marker for the temporary Node runtime bypass
Line 33 sets ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true while the pinned gitleaks/gitleaks-action@v2.3.9 is configured to run on Node 20, so this override can silently persist—add a TODO with an explicit owner/date to remove once the upstream action release that supports Node 24 is adopted.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/security.yaml at line 33, Add a sunset TODO comment above
the ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true override noting the owner and
a target removal date (e.g., "TODO(owner@example.com): remove when
gitleaks/gitleaks-action supports Node 24 by YYYY-MM-DD"); reference the
override key ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION and the pinned action
gitleaks/gitleaks-action@v2.3.9 so it's clear this is a temporary bypass for
Node 20/24 compatibility and should be removed once an upstream release
supporting Node 24 is adopted.
|
🙏 This merge started its CI workflow on Main with GitHub Actions 🖥️ 👍 This merge completed its CI workflow on Main with GitHub Actions 🖥️ |
Summary
Adds
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: "true"to thegitleaks/gitleaks-actionstep insecurity.yaml. This env var is scoped to that step only and has no impact onactions/checkoutwhich is already on node24.Why
GitHub is forcing all actions to run on Node.js 24 by default starting June 2nd, 2026.
gitleaks/gitleaks-action@ff98106(v2.3.9) is still on node20. The upstream node24 migration PR (gitleaks/gitleaks-action#215) has been open since May 5 with no reviews and no release in sight.Since
security.yamlruns as a required workflow across 45 repos, a single central fix is the only way to address all instances before the deadline.ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSIONis GitHub's documented opt-out mechanism as stated in their own deprecation notice.Validation
Code search across all 472
tatari-tvrepos confirmedgitleaks/gitleaks-actionis only referenced in this file — no per-repo usages exist. This PR is the complete fix for all 45 affected repos.Test plan
conductor)Required Workflows Securityjob annotations🤖 Planned with Claude Code