Skip to content

Releases: cosmichackerx/node24-ready

v0.8.0

Choose a tag to compare

@cosmichackerx cosmichackerx released this 03 Oct 11:35
981d1f1
  • New rule codeql-action-v3 (dated deadline with month precision): github/codeql-action/*@v3 (tags, or a SHA whose comment names a v3 tag). GitHub deprecates CodeQL Action v3 in December 2026 without naming a day, so the finding gives a day range ("59 to 89 days"), never a single date, and is never an error (deprecation means no new updates). Source: GitHub changelog 2025-10-28. --no-deadlines skips it.
  • 109 tests; no oracle exists for a GitHub scheduling decision, so the rule rests on the cited page (see README).

v0.7.0 - Docker Content Trust in Dockerfiles, compose, k8s, scripts

Choose a tag to compare

@cosmichackerx cosmichackerx released this 03 Oct 10:39
9db272c

0.7.0 - 2026-10-03

  • Docker Content Trust outside .github (issue #27): the docker-content-trust rule now also reads Dockerfiles/Containerfiles, Compose files, Kubernetes manifests (env as name:/value: pairs or flow maps) and other YAML, *.sh, Makefiles, .env* files, and recognises --disable-content-trust=false and the old ENV DOCKER_CONTENT_TRUST 1 form. An explicit Dockerfile path works and is no longer read as a workflow. --no-deadlines skips all of it.

v0.6.0 - --fix-runners

Choose a tag to compare

@cosmichackerx cosmichackerx released this 03 Oct 10:31
017211d

0.6.0 - 2026-10-03

  • --fix-runners (issue #26): rewrites retiring runs-on labels one generation up (macos-14* -> macos-15*, ubuntu-22.04* -> ubuntu-24.04*), in scalars, lists and matrix entries, with --dry-run diffs, CRLF safety, idempotence and a caveat line per label. Opt-in; --fix is unchanged.
  • Runner findings now carry labelFix (position of the label text, from, to, caveat) in --format json.

v0.5.0 - dated CI deadlines

Choose a tag to compare

@cosmichackerx cosmichackerx released this 03 Oct 10:07
8d2d941

0.4.1 - 2026-10-03

  • Weekly runtime watcher (scripts/watch/watch-runtimes.mjs, .github/workflows/runtime-watch.yml): Node release schedule vs src/eol.ts, documented runs.using values, Node-related changelog entries. One deduplicated issue.
  • NODE_EOL now has Node 27 (found by the watcher).

0.4.0 - 2026-10-03

  • --pin-only (issue #7): replace tag refs by the commit SHA they point to now, with the most specific release as a comment; same major, no upgrade, branches and existing SHAs untouched, idempotent, --dry-run supported (unified diff that git apply accepts), CRLF safe. Implemented with a shared edit planner (planEdits) that --fix now uses too.

node24-ready 0.4.1

Choose a tag to compare

@cosmichackerx cosmichackerx released this 03 Oct 06:52
af7f156
  • Weekly runtime watcher (scripts/watch/watch-runtimes.mjs, .github/workflows/runtime-watch.yml): Node release schedule vs src/eol.ts, documented runs.using values, Node-related changelog entries. One deduplicated issue.
  • NODE_EOL now has Node 27 (found by the watcher).

v0.4.0: --pin-only

Choose a tag to compare

@cosmichackerx cosmichackerx released this 02 Oct 20:40
6bb9349

What's new

  • --pin-only (issue #7): replaces tag refs by the commit SHA they point to today, with the most specific release on that commit as a comment. Same major, no upgrade; branch refs, existing SHAs, local and docker actions are untouched and listed on stderr. Idempotent; --dry-run prints a unified diff that git apply accepts; CRLF safe.
  • --fix and --pin-only share one edit planner (no change to --fix behaviour; the existing tests still pass).

Verified

  • 65 tests pass; CI green on Ubuntu, Windows and macOS (Node 20/22/24).
  • Live check against github.com: actions/checkout@v4 resolved to the commit that v4.4.0 points to (confirmed with git ls-remote), actions/setup-node@v4.1.0 to its tag commit; the output passes git apply --check.

Not verified

  • Only the first 300 tags of a repository are searched; a moving tag can change between the lookup and the merge.
  • Marketplace listing remains a manual step for the repository owner.

v0.3.0: rate-limit fallback, --fix --dry-run, corpus scripts

Choose a tag to compare

@cosmichackerx cosmichackerx released this 02 Oct 19:58
83a5534

What's new

  • Rate-limit fallback (#5): at the REST API limit, action.yml files are read from raw.githubusercontent.com and tags are listed with git ls-remote (public repositories; your token is never passed to git). The summary and one stderr line say how many lookups used it; --no-fallback restores the hard stop.
  • --fix --dry-run (#7, first half): prints a unified diff that git apply accepts (LF and CRLF files) and writes nothing. --pin-only is still open.
  • Corpus scripts (#8): scripts/corpus/fetch.py and compare.py reproduce the precision measurement. Re-run on the same 240 repositories: 1264/1277 distinct references agree with the independent checker (99.0 %), 13 disagreements (hand-check of that run not repeated this time).

Verified vs not

  • Fallback verified against the real raw.githubusercontent.com and git ls-remote using an API stub that always answers 403/rate-limited; unit tests use local look-alike servers and real git ls-remote output.
  • The agreement figure compares two implementations by the same author; it is not GitHub-runtime ground truth.
  • Marketplace: action.yml has the metadata; publishing is a manual step for the repository owner.

Full list: CHANGELOG.md

v0.2.0: setup-node EOL rule, ignore list with expiry, PR mode, cache

Choose a tag to compare

@cosmichackerx cosmichackerx released this 02 Oct 18:58
9a57870

0.2.0 - 2026-10-03

  • New rule setup-node-eol (issue #1): end-of-life Node.js versions in actions/setup-node (node-version, version files, lts/<codename>, matrix expansion).
  • .node24-ready.json ignore list with mandatory reason and expires; expired entries become ignore-expired warnings; unused entries are listed; SARIF suppressions (issue #2).
  • --changed-since <ref> PR mode and Action input changed-since; the ignore list is read from the base ref (issue #3).
  • --cache-dir / NODE24_READY_CACHE: ETag revalidation and SHA-pin caching to stay within rate limits (issue #5).
  • Precision work from a 240-repository corpus (see README): runs.plugin actions (e.g. actions/checkout@v1) are no longer "unresolved"; steps inside - parallel: groups are scanned; workflows rejected by the YAML library are line-scanned and reported as file-unparseable.
  • --fix still refuses to combine with --changed-since.

v0.1.1 - --fix reports what is left

Choose a tag to compare

@cosmichackerx cosmichackerx released this 02 Oct 18:01
ae22168

0.1.1 - 2026-10-02

  • --fix no longer prints the findings it just fixed; the report lists only what is left (for example actions without a node24 release).

v0.1.0 - first release

Choose a tag to compare

@cosmichackerx cosmichackerx released this 02 Oct 17:55

First release.

  • Scans .github/workflows/*.yml and action.yml files for uses: references and reads the real runs.using of the pinned ref through the GitHub API (cached, concurrency-limited, retries on 5xx).
  • Looks through composite actions and reusable workflows (depth 4, cycle-safe).
  • Rules: action-runtime-deprecated, action-runtime-nested, action-runtime-unresolved, local-action-runtime.
  • Suggests the smallest newer major whose release declares a supported runtime, with the commit SHA for pinning.
  • --fix rewrites tag refs and SHA pins (adding the version as a comment); CRLF files are preserved.
  • Output: text, markdown, json, GitHub annotations, SARIF 2.1.0 (validated against the official schema in tests).
  • Composite GitHub Action with a committed bundle (no nested actions, no setup-node), Marketplace metadata.

See the README for real output, rules, limitations and how it compares to existing tools.

Marketplace: the action metadata (name, description <=125 chars, branding) is ready; publishing to the Marketplace is a manual step by the owner.