Skip to content

Upgrade actions/checkout and actions/setup-java to v5 - #46

Merged
merlimat merged 1 commit into
streamnative:masterfrom
merlimat:upgrade-actions-v5
Oct 3, 2026
Merged

merlimat merged 1 commit into
streamnative:masterfrom
merlimat:upgrade-actions-v5

Conversation

@merlimat

@merlimat merlimat commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

Problem

actions/checkout@v4 and actions/setup-java@v4 target Node.js 20, which the runners now force onto Node.js 24. @v4 of setup-java also resolves to v4.9.1 now, a release that only adds a deprecation warning: v4 gets no more updates. Both workflows warn on every run, the release pipeline included.

Example

The v0.9.0 Publish to Maven Central run, and every CI - Unit run on master:

! Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-java@v4.
! setup-java v4 is deprecated and will no longer receive updates. Please migrate to actions/setup-java@v5.

from

      - name: Checkout
        uses: actions/checkout@v4

      - name: Set up JDK 17
        uses: actions/setup-java@v4

Change

ci-unit.yaml and publish.yaml use actions/checkout@v5 and actions/setup-java@v5, with the same inputs. I compared the releases that @v4 and @v5 point to today: checkout v4.4.0 → v5.1.0 and setup-java v4.9.1 → v5.7.0.

  • checkout: only runs.using changes, from node20 to node24, and src/ is identical. Its breaking change in v5.1.0 (allow-unsafe-pr-checkout) only affects pull_request_target and workflow_run, which neither workflow uses. v4.4.0 already has it too.
  • setup-java inputs: none of the inputs these workflows pass was renamed or removed. action.yml no longer marks distribution as required, but the action still fails without it unless the version comes from a .sdkmanrc. We pass temurin. jdkFile became jdk-file, and we don't use it.
  • Release path: settings.xml still gets the central server with ${env.SONATYPE_USERNAME} / ${env.SONATYPE_PASSWORD}, and the gpg.passphrase server with ${env.GPG_PASSPHRASE} that maven-gpg-plugin 1.6 reads. The key is still imported into the default keyring, so "Show GPG key info" still lists it, and the post step still removes it. The key import/delete code and cleanup-java.ts are unchanged.
  • New defaults: settings.xml now sets <interactiveMode>false</interactiveMode>, and the action exports MAVEN_ARGS=-ntp. The workflows already pass both as -B -ntp. verify-signature defaults to off, and set-default defaults to on, the same as v4's behaviour.
  • Maven cache: the path (~/.m2/repository) and key format are unchanged. The key now also hashes .mvn/wrapper/maven-wrapper.properties and .mvn/extensions.xml, which this repo doesn't have.
  • Problem matchers: setup-java v5 adds javac matchers. No line in the CI - Unit log matches them. The release build's javadoc warnings will show up as warning annotations on the publish run: the v0.9.0 run printed 324 lines like DescriptorConverter.java:87: warning: no @return.

This moves to v5 rather than setup-java v6 because v6 no longer writes the gpg.passphrase server. It sets gpg.passphraseEnvName instead, which maven-gpg-plugin only reads from 3.2.0 on, so v6 would also need a plugin upgrade.

The run's third notice, that ubuntu-latest moves to Ubuntu 26 from October 19, 2026, is out of scope here. Both jobs stay on ubuntu-latest.

Testing

  • actionlint 1.7.11 reports one finding: SC2086 on $VERSION in "Set version from tag". That step is unchanged here, and master gets the same finding.
  • CI - Unit on this PR runs with actions/checkout@v5 and actions/setup-java@v5. That covers the JDK install, the generated settings.xml, MAVEN_ARGS, and the Maven cache restore and save.
  • publish.yaml only runs when a v* tag is pushed, so it can only be fully verified on the next release tag. The parts CI - Unit doesn't exercise are the central server credentials and the GPG key import and removal. They go through setup-java code that is the same in v4.9.1 and v5.7.0.

actions/checkout@v4 and actions/setup-java@v4 target Node.js 20, which
the runners now force onto Node.js 24 with a warning on every run, and
setup-java v4 adds its own warning that it is deprecated and will get
no more updates. The v5 releases of both run on Node.js 24.

The inputs stay the same: none of the ones these workflows pass was
renamed or removed in v5. setup-java v5 still writes the central and
gpg.passphrase servers into settings.xml and imports the signing key
into the default keyring, as the release profile's maven-gpg-plugin 1.6
and the "Show GPG key info" step expect.
@merlimat
merlimat merged commit dea9037 into streamnative:master Oct 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant