Repository navigation
Upgrade actions/checkout and actions/setup-java to v5 - #46
Merged
Merged
Conversation
actions/checkout@v4 and actions/setup-java@v4 target Node.js 20, which the runners now force onto Node.js 24 with a warning on every run, and setup-java v4 adds its own warning that it is deprecated and will get no more updates. The v5 releases of both run on Node.js 24. The inputs stay the same: none of the ones these workflows pass was renamed or removed in v5. setup-java v5 still writes the central and gpg.passphrase servers into settings.xml and imports the signing key into the default keyring, as the release profile's maven-gpg-plugin 1.6 and the "Show GPG key info" step expect.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
actions/checkout@v4andactions/setup-java@v4target Node.js 20, which the runners now force onto Node.js 24.@v4of setup-java also resolves to v4.9.1 now, a release that only adds a deprecation warning: v4 gets no more updates. Both workflows warn on every run, the release pipeline included.Example
The v0.9.0 Publish to Maven Central run, and every CI - Unit run on master:
from
Change
ci-unit.yamlandpublish.yamluseactions/checkout@v5andactions/setup-java@v5, with the same inputs. I compared the releases that@v4and@v5point to today: checkout v4.4.0 → v5.1.0 and setup-java v4.9.1 → v5.7.0.runs.usingchanges, fromnode20tonode24, andsrc/is identical. Its breaking change in v5.1.0 (allow-unsafe-pr-checkout) only affectspull_request_targetandworkflow_run, which neither workflow uses. v4.4.0 already has it too.action.ymlno longer marksdistributionas required, but the action still fails without it unless the version comes from a.sdkmanrc. We passtemurin.jdkFilebecamejdk-file, and we don't use it.settings.xmlstill gets thecentralserver with${env.SONATYPE_USERNAME}/${env.SONATYPE_PASSWORD}, and thegpg.passphraseserver with${env.GPG_PASSPHRASE}that maven-gpg-plugin 1.6 reads. The key is still imported into the default keyring, so "Show GPG key info" still lists it, and the post step still removes it. The key import/delete code andcleanup-java.tsare unchanged.settings.xmlnow sets<interactiveMode>false</interactiveMode>, and the action exportsMAVEN_ARGS=-ntp. The workflows already pass both as-B -ntp.verify-signaturedefaults to off, andset-defaultdefaults to on, the same as v4's behaviour.~/.m2/repository) and key format are unchanged. The key now also hashes.mvn/wrapper/maven-wrapper.propertiesand.mvn/extensions.xml, which this repo doesn't have.DescriptorConverter.java:87: warning: no @return.This moves to v5 rather than setup-java v6 because v6 no longer writes the
gpg.passphraseserver. It setsgpg.passphraseEnvNameinstead, which maven-gpg-plugin only reads from 3.2.0 on, so v6 would also need a plugin upgrade.The run's third notice, that
ubuntu-latestmoves to Ubuntu 26 from October 19, 2026, is out of scope here. Both jobs stay onubuntu-latest.Testing
actionlint1.7.11 reports one finding: SC2086 on$VERSIONin "Set version from tag". That step is unchanged here, and master gets the same finding.actions/checkout@v5andactions/setup-java@v5. That covers the JDK install, the generatedsettings.xml,MAVEN_ARGS, and the Maven cache restore and save.publish.yamlonly runs when av*tag is pushed, so it can only be fully verified on the next release tag. The parts CI - Unit doesn't exercise are thecentralserver credentials and the GPG key import and removal. They go through setup-java code that is the same in v4.9.1 and v5.7.0.