Repository navigation
Releases: cosmichackerx/node24-ready
Releases · cosmichackerx/node24-ready
Release list
v0.8.0
- New rule
codeql-action-v3(dated deadline with month precision):github/codeql-action/*@v3(tags, or a SHA whose comment names a v3 tag). GitHub deprecates CodeQL Action v3 in December 2026 without naming a day, so the finding gives a day range ("59 to 89 days"), never a single date, and is never an error (deprecation means no new updates). Source: GitHub changelog 2025-10-28.--no-deadlinesskips it. - 109 tests; no oracle exists for a GitHub scheduling decision, so the rule rests on the cited page (see README).
v0.7.0 - Docker Content Trust in Dockerfiles, compose, k8s, scripts
0.7.0 - 2026-10-03
- Docker Content Trust outside
.github(issue #27): thedocker-content-trustrule now also reads Dockerfiles/Containerfiles, Compose files, Kubernetes manifests (envasname:/value:pairs or flow maps) and other YAML,*.sh, Makefiles,.env*files, and recognises--disable-content-trust=falseand the oldENV DOCKER_CONTENT_TRUST 1form. An explicit Dockerfile path works and is no longer read as a workflow.--no-deadlinesskips all of it.
v0.6.0 - --fix-runners
0.6.0 - 2026-10-03
--fix-runners(issue #26): rewrites retiringruns-onlabels one generation up (macos-14*->macos-15*,ubuntu-22.04*->ubuntu-24.04*), in scalars, lists and matrix entries, with--dry-rundiffs, CRLF safety, idempotence and a caveat line per label. Opt-in;--fixis unchanged.- Runner findings now carry
labelFix(position of the label text, from, to, caveat) in--format json.
v0.5.0 - dated CI deadlines
0.4.1 - 2026-10-03
- Weekly runtime watcher (
scripts/watch/watch-runtimes.mjs,.github/workflows/runtime-watch.yml): Node release schedule vssrc/eol.ts, documentedruns.usingvalues, Node-related changelog entries. One deduplicated issue. NODE_EOLnow has Node 27 (found by the watcher).
0.4.0 - 2026-10-03
--pin-only(issue #7): replace tag refs by the commit SHA they point to now, with the most specific release as a comment; same major, no upgrade, branches and existing SHAs untouched, idempotent,--dry-runsupported (unified diff thatgit applyaccepts), CRLF safe. Implemented with a shared edit planner (planEdits) that--fixnow uses too.
node24-ready 0.4.1
- Weekly runtime watcher (
scripts/watch/watch-runtimes.mjs,.github/workflows/runtime-watch.yml): Node release schedule vssrc/eol.ts, documentedruns.usingvalues, Node-related changelog entries. One deduplicated issue. NODE_EOLnow has Node 27 (found by the watcher).
v0.4.0: --pin-only
What's new
--pin-only(issue #7): replaces tag refs by the commit SHA they point to today, with the most specific release on that commit as a comment. Same major, no upgrade; branch refs, existing SHAs, local and docker actions are untouched and listed on stderr. Idempotent;--dry-runprints a unified diff thatgit applyaccepts; CRLF safe.--fixand--pin-onlyshare one edit planner (no change to--fixbehaviour; the existing tests still pass).
Verified
- 65 tests pass; CI green on Ubuntu, Windows and macOS (Node 20/22/24).
- Live check against github.com:
actions/checkout@v4resolved to the commit thatv4.4.0points to (confirmed withgit ls-remote),actions/setup-node@v4.1.0to its tag commit; the output passesgit apply --check.
Not verified
- Only the first 300 tags of a repository are searched; a moving tag can change between the lookup and the merge.
- Marketplace listing remains a manual step for the repository owner.
v0.3.0: rate-limit fallback, --fix --dry-run, corpus scripts
What's new
- Rate-limit fallback (#5): at the REST API limit,
action.ymlfiles are read fromraw.githubusercontent.comand tags are listed withgit ls-remote(public repositories; your token is never passed to git). The summary and one stderr line say how many lookups used it;--no-fallbackrestores the hard stop. --fix --dry-run(#7, first half): prints a unified diff thatgit applyaccepts (LF and CRLF files) and writes nothing.--pin-onlyis still open.- Corpus scripts (#8):
scripts/corpus/fetch.pyandcompare.pyreproduce the precision measurement. Re-run on the same 240 repositories: 1264/1277 distinct references agree with the independent checker (99.0 %), 13 disagreements (hand-check of that run not repeated this time).
Verified vs not
- Fallback verified against the real raw.githubusercontent.com and
git ls-remoteusing an API stub that always answers 403/rate-limited; unit tests use local look-alike servers and realgit ls-remoteoutput. - The agreement figure compares two implementations by the same author; it is not GitHub-runtime ground truth.
- Marketplace:
action.ymlhas the metadata; publishing is a manual step for the repository owner.
Full list: CHANGELOG.md
v0.2.0: setup-node EOL rule, ignore list with expiry, PR mode, cache
0.2.0 - 2026-10-03
- New rule
setup-node-eol(issue #1): end-of-life Node.js versions inactions/setup-node(node-version, version files,lts/<codename>, matrix expansion). .node24-ready.jsonignore list with mandatoryreasonandexpires; expired entries becomeignore-expiredwarnings; unused entries are listed; SARIFsuppressions(issue #2).--changed-since <ref>PR mode and Action inputchanged-since; the ignore list is read from the base ref (issue #3).--cache-dir/NODE24_READY_CACHE: ETag revalidation and SHA-pin caching to stay within rate limits (issue #5).- Precision work from a 240-repository corpus (see README):
runs.pluginactions (e.g.actions/checkout@v1) are no longer "unresolved"; steps inside- parallel:groups are scanned; workflows rejected by the YAML library are line-scanned and reported asfile-unparseable. --fixstill refuses to combine with--changed-since.
v0.1.1 - --fix reports what is left
0.1.1 - 2026-10-02
--fixno longer prints the findings it just fixed; the report lists only what is left (for example actions without a node24 release).
v0.1.0 - first release
First release.
- Scans
.github/workflows/*.ymlandaction.ymlfiles foruses:references and reads the realruns.usingof the pinned ref through the GitHub API (cached, concurrency-limited, retries on 5xx). - Looks through composite actions and reusable workflows (depth 4, cycle-safe).
- Rules:
action-runtime-deprecated,action-runtime-nested,action-runtime-unresolved,local-action-runtime. - Suggests the smallest newer major whose release declares a supported runtime, with the commit SHA for pinning.
--fixrewrites tag refs and SHA pins (adding the version as a comment); CRLF files are preserved.- Output: text, markdown, json, GitHub annotations, SARIF 2.1.0 (validated against the official schema in tests).
- Composite GitHub Action with a committed bundle (no nested actions, no setup-node), Marketplace metadata.
See the README for real output, rules, limitations and how it compares to existing tools.
Marketplace: the action metadata (name, description <=125 chars, branding) is ready; publishing to the Marketplace is a manual step by the owner.