Skip to content

🔧 chore(deps): land the queued dependency updates - #103

Merged
cwest merged 1 commit into
mainfrom
wt/t_6a27c143-chore-deps-land-the-queued-dependency-up
Aug 8, 2026
Merged

cwest merged 1 commit into
mainfrom
wt/t_6a27c143-chore-deps-land-the-queued-dependency-up

Conversation

@cwest

@cwest cwest commented Aug 8, 2026

Copy link
Copy Markdown
Owner

What

Lands six queued dependency updates as one branch/PR so the Pages deploy
path is proven as a unit rather than mutated by six separate merges. Four
of the six touch the Pages deploy path, so a bad bump breaks publishing
rather than the build — bundling proves them together.

Update From → To File
@astrojs/starlight 0.41.6 → 0.41.7 site/package.json, site/package-lock.json
dorny/paths-filter 3 → 4 .github/workflows/ci.yml
actions/setup-node 6 → 7 ci.yml, docs.yml
actions/configure-pages 5 → 6 docs.yml
actions/upload-pages-artifact 4 → 5 docs.yml
actions/deploy-pages 4 → 5 docs.yml

Major-bump input verification (against each action.yml at target)

Every major action bump is a Node-24 runtime update; each was checked for
breaking input changes against the action's release notes AND its
action.yml inputs at the pinned version. All with: blocks still match.

  • dorny/paths-filter v4.0.0 — runtime bump to node24 only
    (feat: update action runtime to node24 dorny/paths-filter#294). filters input unchanged and still present.
  • actions/setup-node v7.0.0 — ESM migration + new cache outputs; removed
    a dummy NODE_AUTH_TOKEN export. Inputs node-version, cache,
    cache-dependency-path all still present.
  • actions/configure-pages v6.0.0 — node24 upgrade + dep bumps. Used with
    no with: block, so no input surface to break.
  • actions/upload-pages-artifact v5.0.0 — internal upload-artifact bumped
    to v7; added optional include-hidden-files input (additive). path
    input unchanged and still present.
  • actions/deploy-pages v5.0.0 — node24 + removed a file-permissions error
    message. Used with no with: block, so no input surface to break.

Each pinned floating tag resolves to a real published release SHA:
paths-filter@v4 → ceb8a2b, setup-node@v7 → 8207627,
configure-pages@v6 → 45bfe01, upload-pages-artifact@v5 → fc324d3,
deploy-pages@v5 → cd2ce8f.

Proof (run output, not claims)

Starlight bump — site/:

$ npm ci
added 373 packages, and audited 374 packages in 2s
found 0 vulnerabilities

$ npm test
[build] Complete!
✔ every doc is served at its clean URL
✔ legacy _generated/* paths redirect to the clean URL (not 404)
✔ sitemap lists ONLY clean URLs — no _generated path
✔ every indexable page carries the social card and icon tags
ℹ tests 11
ℹ pass 11
ℹ fail 0

Workflow bumps — both files parse and refs resolve:

$ python3 yaml_check.py
.github/workflows/ci.yml OK
.github/workflows/docs.yml OK
# all 5 action refs → real tag SHAs (no MISSING)

Go tree unaffected (no Go changed) — sanity confirmed:

$ gofmt -l .        # (empty)
$ go vet ./...      # (clean)
$ CGO_ENABLED=0 go build ./...   # build OK

Pages deploy path

The docs.yml Pages deploy runs only on push to main / release, so the
live-deploy verification happens post-merge (out of the PR's reach). The
pre-merge proof above establishes: valid workflow YAML, all upgraded action
refs resolve, every with: block matches the target action.yml, and the
site builds + passes its assertion suite against starlight 0.41.7.

Closes

Supersedes and closes the six individual dependabot PRs, landed here as one:
#100, #99, #91, #90, #89, #88.

Bundle six queued updates into one change so the Pages deploy path is
proven as a unit rather than mutated by six separate merges.

- @astrojs/starlight 0.41.6 -> 0.41.7 (site/)
- dorny/paths-filter 3 -> 4
- actions/setup-node 6 -> 7
- actions/configure-pages 5 -> 6
- actions/upload-pages-artifact 4 -> 5
- actions/deploy-pages 4 -> 5

Each major action bump is a Node 24 runtime update with no breaking
input changes; the workflows' with: blocks were verified against each
action.yml at the target version and still match.

@cwest cwest left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No changes needed.

The six bumps land as one branch, one PR, with nothing in the diff beyond the version lines. I checked each major action bump's inputs against its action.yml at the target tag: paths-filter@v4 still takes filters, setup-node@v7 still takes node-version/cache/cache-dependency-path, upload-pages-artifact@v5 still takes path, and configure-pages@v6 and deploy-pages@v5 are used with no inputs. Nothing the workflows rely on was removed or renamed — the majors are Node 24 runtime bumps.

The Pages deploy path is intact: docs.yml keeps its permissions, concurrency group, github-pages environment, and build→deploy job structure; only the action version pins moved.

Starlight 0.41.7 builds and tests clean. Ran npm ci (0 vulnerabilities) and npm test off the PR head in a fresh clone: 11 passed, 0 failed, covering the build plus the clean-URL, redirect, sitemap, and social-card assertions.

CI is green across changes, build-test, lint, site, analyze (go), and CodeQL. The six dependabot PRs are closed against this one.

The live deploy only runs on push to main, so the actual okfctl.dev serve check happens after merge — worth a quick look at the site once it lands.

@cwest
cwest merged commit ca6c946 into main Aug 8, 2026
6 checks passed
@cwest
cwest deleted the wt/t_6a27c143-chore-deps-land-the-queued-dependency-up branch August 17, 2026 17:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant