🔧 chore(deps): land the queued dependency updates - #103
Conversation
Bundle six queued updates into one change so the Pages deploy path is proven as a unit rather than mutated by six separate merges. - @astrojs/starlight 0.41.6 -> 0.41.7 (site/) - dorny/paths-filter 3 -> 4 - actions/setup-node 6 -> 7 - actions/configure-pages 5 -> 6 - actions/upload-pages-artifact 4 -> 5 - actions/deploy-pages 4 -> 5 Each major action bump is a Node 24 runtime update with no breaking input changes; the workflows' with: blocks were verified against each action.yml at the target version and still match.
cwest
left a comment
There was a problem hiding this comment.
No changes needed.
The six bumps land as one branch, one PR, with nothing in the diff beyond the version lines. I checked each major action bump's inputs against its action.yml at the target tag: paths-filter@v4 still takes filters, setup-node@v7 still takes node-version/cache/cache-dependency-path, upload-pages-artifact@v5 still takes path, and configure-pages@v6 and deploy-pages@v5 are used with no inputs. Nothing the workflows rely on was removed or renamed — the majors are Node 24 runtime bumps.
The Pages deploy path is intact: docs.yml keeps its permissions, concurrency group, github-pages environment, and build→deploy job structure; only the action version pins moved.
Starlight 0.41.7 builds and tests clean. Ran npm ci (0 vulnerabilities) and npm test off the PR head in a fresh clone: 11 passed, 0 failed, covering the build plus the clean-URL, redirect, sitemap, and social-card assertions.
CI is green across changes, build-test, lint, site, analyze (go), and CodeQL. The six dependabot PRs are closed against this one.
The live deploy only runs on push to main, so the actual okfctl.dev serve check happens after merge — worth a quick look at the site once it lands.
What
Lands six queued dependency updates as one branch/PR so the Pages deploy
path is proven as a unit rather than mutated by six separate merges. Four
of the six touch the Pages deploy path, so a bad bump breaks publishing
rather than the build — bundling proves them together.
@astrojs/starlightsite/package.json,site/package-lock.jsondorny/paths-filter.github/workflows/ci.ymlactions/setup-nodeci.yml,docs.ymlactions/configure-pagesdocs.ymlactions/upload-pages-artifactdocs.ymlactions/deploy-pagesdocs.ymlMajor-bump input verification (against each
action.ymlat target)Every major action bump is a Node-24 runtime update; each was checked for
breaking input changes against the action's release notes AND its
action.ymlinputs at the pinned version. Allwith:blocks still match.(feat: update action runtime to node24 dorny/paths-filter#294).
filtersinput unchanged and still present.a dummy
NODE_AUTH_TOKENexport. Inputsnode-version,cache,cache-dependency-pathall still present.no
with:block, so no input surface to break.to v7; added optional
include-hidden-filesinput (additive).pathinput unchanged and still present.
message. Used with no
with:block, so no input surface to break.Each pinned floating tag resolves to a real published release SHA:
paths-filter@v4 → ceb8a2b,setup-node@v7 → 8207627,configure-pages@v6 → 45bfe01,upload-pages-artifact@v5 → fc324d3,deploy-pages@v5 → cd2ce8f.Proof (run output, not claims)
Starlight bump —
site/:Workflow bumps — both files parse and refs resolve:
Go tree unaffected (no Go changed) — sanity confirmed:
Pages deploy path
The
docs.ymlPages deploy runs only on push tomain/ release, so thelive-deploy verification happens post-merge (out of the PR's reach). The
pre-merge proof above establishes: valid workflow YAML, all upgraded action
refs resolve, every
with:block matches the targetaction.yml, and thesite builds + passes its assertion suite against starlight 0.41.7.
Closes
Supersedes and closes the six individual dependabot PRs, landed here as one:
#100, #99, #91, #90, #89, #88.