From 253633b3d475d82d72807944c390f502eefc1d68 Mon Sep 17 00:00:00 2001 From: Julien Danjou Date: Fri, 25 Sep 2026 20:57:21 +0200 Subject: [PATCH] ci: run every GitHub-hosted job on ubuntu-26.04 Pin all eleven hosted jobs to `ubuntu-26.04`: the nine that pinned `ubuntu-24.04` in ci.yaml, plus the two `ubuntu-latest` jobs (actionlint in ci.yaml, deploy in deploy-cf.yaml). An explicit pin is the org convention, and GitHub moves `ubuntu-latest` to 26.04 on its own schedule between 2026-10-19 and 2026-11-19; pinning now means the switch happens here, with CI to show it works, rather than on a date nobody chose. Nothing in these jobs depends on what differs between the 24.04 and 26.04 images. Every Node job installs Node from `.node-version` through setup-node, so the image's default Node (22 -> 24) is never used. No job calls system `python3`, CMake, Clang, OpenSSL or PostgreSQL. actionlint runs as a docker action, and deploy calls a composite Slack action. actionlint 1.7.8 does not know the 26.04 labels, and neither does any later release, so `ubuntu-26.04` would fail the actionlint job as an unknown label. `.github/actionlint.yaml` declares it until actionlint ships it natively. No job was left behind: this repository has no self-hosted, macOS, Windows or arm jobs. deploy-cf.yaml only runs on a push to main, so this pull request's CI does not exercise it; its single step is a Slack webhook call, which does not depend on the image. MRGFY-9715 Co-Authored-By: Claude Opus 5.5 Change-Id: Ic6b77c46fff23961ae085d7edb2b86a4c01dac4f --- .github/actionlint.yaml | 10 ++++++++++ .github/workflows/ci.yaml | 20 ++++++++++---------- .github/workflows/deploy-cf.yaml | 2 +- 3 files changed, 21 insertions(+), 11 deletions(-) create mode 100644 .github/actionlint.yaml diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml new file mode 100644 index 0000000000..115661254a --- /dev/null +++ b/.github/actionlint.yaml @@ -0,0 +1,10 @@ +# actionlint validates `runs-on:` against the GitHub-hosted labels it ships +# with plus the ones declared here. No actionlint release knows the Ubuntu +# 26.04 hosted images yet (GA 2026-09-17), so without this file every job in +# ci.yaml would fail the actionlint job with `label "ubuntu-26.04" is unknown`. +# `self-hosted-runner.labels` is actionlint's only way to add a label; the +# runners are still GitHub-hosted, this repository has no self-hosted ones. +# Drop an entry once the pinned actionlint lists it natively. +self-hosted-runner: + labels: + - ubuntu-26.04 diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index b95b8cdcbc..ba3e5f77c2 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -14,7 +14,7 @@ concurrency: jobs: actionlint: - runs-on: ubuntu-latest + runs-on: ubuntu-26.04 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -26,7 +26,7 @@ jobs: lint: timeout-minutes: 20 - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - name: Checkout 🛎️ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -47,7 +47,7 @@ jobs: test: timeout-minutes: 20 - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - name: Checkout 🛎️ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -68,7 +68,7 @@ jobs: config-examples: timeout-minutes: 10 - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - name: Checkout 🛎️ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -89,7 +89,7 @@ jobs: internal-leaks: timeout-minutes: 5 - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - name: Checkout 🛎️ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -106,7 +106,7 @@ jobs: diagram-tokens: timeout-minutes: 5 - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - name: Checkout 🛎️ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -123,7 +123,7 @@ jobs: orphaned-images: timeout-minutes: 5 - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - name: Checkout 🛎️ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -140,7 +140,7 @@ jobs: build: timeout-minutes: 20 - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - name: Checkout 🛎️ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -167,7 +167,7 @@ jobs: test-broken-links: timeout-minutes: 20 - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 needs: build steps: - name: Checkout 🛎️ @@ -213,7 +213,7 @@ jobs: - orphaned-images - build - test-broken-links - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: # wait-jobs accepts a SKIPPED dependency as well as a successful one. That # is safe only while no job above carries an `if:`: today a job is skipped diff --git a/.github/workflows/deploy-cf.yaml b/.github/workflows/deploy-cf.yaml index f3dcd62015..ea2f448382 100644 --- a/.github/workflows/deploy-cf.yaml +++ b/.github/workflows/deploy-cf.yaml @@ -14,7 +14,7 @@ concurrency: jobs: deploy: timeout-minutes: 5 - runs-on: ubuntu-latest + runs-on: ubuntu-26.04 steps: - name: Deployment start if: always() && github.event_name == 'push' && github.ref == 'refs/heads/main'