KEMBAR78
Upgrade to node 24 by salmanmkc · Pull Request #1164 · actions/setup-python · GitHub
Skip to content

Conversation

@salmanmkc
Copy link
Contributor

Upgrade to node 24 since runner release has node 24 support.

Description:
Describe your changes.

Related issue:
Add link to the related issue.

Check list:

  • Mark if documentation changes are required.
  • Mark if tests were added or updated to cover the changes.

@salmanmkc salmanmkc marked this pull request as ready for review August 8, 2025 04:06
@Copilot Copilot AI review requested due to automatic review settings August 8, 2025 04:06
@salmanmkc salmanmkc requested a review from a team as a code owner August 8, 2025 04:06
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Upgrades the Node.js runtime from version 20 to version 24 for a GitHub Action, leveraging runner support for Node 24.

  • Updates Node.js runtime specification in GitHub Action configuration
  • Upgrades Node.js type definitions to match the new runtime version
  • Sets minimum Node.js engine requirement to enforce compatibility

Reviewed Changes

Copilot reviewed 4 out of 5 changed files in this pull request and generated no comments.

File Description
package.json Adds Node.js engine requirement and updates @types/node dependency
action.yml Changes GitHub Action runtime from node20 to node24
.licenses/npm/undici-types.dep.yml Updates undici-types license tracking for new version
.licenses/npm/@types/node.dep.yml Updates @types/node license tracking for new version

priya-kinthali
priya-kinthali previously approved these changes Aug 19, 2025
aparnajyothi-y
aparnajyothi-y previously approved these changes Aug 19, 2025
@priya-kinthali priya-kinthali dismissed stale reviews from aparnajyothi-y and themself via c7178f6 August 26, 2025 08:32
…advanced-usage.md

Updated GitHub Actions to use newer versions of checkout and setup-python actions.
priya-kinthali
priya-kinthali previously approved these changes Aug 26, 2025
aparnajyothi-y
aparnajyothi-y previously approved these changes Aug 26, 2025
@reneleonhardt
Copy link

Sets minimum Node.js engine requirement to enforce compatibility

Is enforcing node 24 needed for this upgrade to work?
I imagine not all popular runners install node 24 because it isn't even LTS yet (2025-10-28).
https://github.com/nodejs/release#release-schedule

@salmanmkc
Copy link
Contributor Author

salmanmkc commented Aug 26, 2025

Sets minimum Node.js engine requirement to enforce compatibility

Is enforcing node 24 needed for this upgrade to work? I imagine not all popular runners install node 24 because it isn't even LTS yet (2025-10-28). https://github.com/nodejs/release#release-schedule

Hi good question. And my apologies, I'm unsure what you mean by not all popular runners? All the hosted runners at the moment are on 2.238.0. Self-hosted runners should auto-update and if not, then they should be upgraded by the customers eventually. The thing is the actions.yml file targets node24 as well, so it should not be able to run on node 20 because of the actions.yml file.

Also this is a major bump, so we could cut a minor version before this 5.0.0 release.

@reneleonhardt
Copy link

I can only see that most developers don't update their workflows and that node 22 is the latest LTS.

https://github.com/actions/runner-images/blob/main/images/ubuntu/Ubuntu2204-Readme.md?plain=1#L21

Node.js 20.19.4
https://github.com/actions/runner-images/blob/main/images/ubuntu/Ubuntu2404-Readme.md?plain=1#L19
Node.js 20.19.4

The new ARM images should be similar (but they don't document version numbers):
https://github.com/actions/partner-runner-images/blob/main/images/arm-ubuntu-22-image.md
https://github.com/actions/partner-runner-images/blob/main/images/arm-ubuntu-24-image.md

The official runner is still based on ubuntu-22.04 (jammy)
https://github.com/actions/runner/blob/main/images/Dockerfile

Even the latest ubuntu-25.04 only ships node 20:
https://packages.ubuntu.com/search?keywords=nodejs&searchon=names&suite=plucky&section=all

So maybe it would be better not to enforce node 24 as even 2.238.0 seems to require workflow changes:

  env:
    FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true

actions/runner#3948

If possible for this change of course 😄

@aparnajyothi-y aparnajyothi-y dismissed stale reviews from priya-kinthali and themself via 9b03c62 September 2, 2025 16:11
@aparnajyothi-y
Copy link
Contributor

Hello Everyone, Thanks for the feedback!
We are planning to move forward with this change as a major version bump since it aligns with the runner support for Node.js 24. We recognize that Node 24 is not yet LTS, and based on community feedback we’ll closely monitor adoption. If needed, we will revisit this decision and release updates (e.g. minor or patch versions) to adjust compatibility as required.

@HarithaVattikuti HarithaVattikuti merged commit e797f83 into actions:main Sep 4, 2025
1299 checks passed
mergify bot added a commit to ArcadeData/arcadedb that referenced this pull request Sep 8, 2025
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.6.0 to 6.0.0.
Release notes

*Sourced from [actions/setup-python's releases](https://github.com/actions/setup-python/releases).*

> v6.0.0
> ------
>
> What's Changed
> --------------
>
> ### Breaking Changes
>
> * Upgrade to node 24 by [`@​salmanmkc`](https://github.com/salmanmkc) in [actions/setup-python#1164](https://redirect.github.com/actions/setup-python/pull/1164)
>
> Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. [See Release Notes](https://github.com/actions/runner/releases/tag/v2.327.1)
>
> ### Enhancements:
>
> * Add support for `pip-version` by [`@​priyagupta108`](https://github.com/priyagupta108) in [actions/setup-python#1129](https://redirect.github.com/actions/setup-python/pull/1129)
> * Enhance reading from .python-version by [`@​krystof-k`](https://github.com/krystof-k) in [actions/setup-python#787](https://redirect.github.com/actions/setup-python/pull/787)
> * Add version parsing from Pipfile by [`@​aradkdj`](https://github.com/aradkdj) in [actions/setup-python#1067](https://redirect.github.com/actions/setup-python/pull/1067)
>
> ### Bug fixes:
>
> * Clarify pythonLocation behaviour for PyPy and GraalPy in environment variables by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1183](https://redirect.github.com/actions/setup-python/pull/1183)
> * Change missing cache directory error to warning by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1182](https://redirect.github.com/actions/setup-python/pull/1182)
> * Add Architecture-Specific PATH Management for Python with --user Flag on Windows by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1122](https://redirect.github.com/actions/setup-python/pull/1122)
> * Include python version in PyPy python-version output by [`@​cdce8p`](https://github.com/cdce8p) in [actions/setup-python#1110](https://redirect.github.com/actions/setup-python/pull/1110)
> * Update docs: clarification on pip authentication with setup-python by [`@​priya-kinthali`](https://github.com/priya-kinthali) in [actions/setup-python#1156](https://redirect.github.com/actions/setup-python/pull/1156)
>
> ### Dependency updates:
>
> * Upgrade idna from 2.9 to 3.7 in /**tests**/data by [`@​dependabot`](https://github.com/dependabot)[bot] in [actions/setup-python#843](https://redirect.github.com/actions/setup-python/pull/843)
> * Upgrade form-data to fix critical vulnerabilities [#182](https://redirect.github.com/actions/setup-python/issues/182) & [#183](https://redirect.github.com/actions/setup-python/issues/183) by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1163](https://redirect.github.com/actions/setup-python/pull/1163)
> * Upgrade setuptools to 78.1.1 to fix path traversal vulnerability in PackageIndex.download by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1165](https://redirect.github.com/actions/setup-python/pull/1165)
> * Upgrade actions/checkout from 4 to 5 by [`@​dependabot`](https://github.com/dependabot)[bot] in [actions/setup-python#1181](https://redirect.github.com/actions/setup-python/pull/1181)
> * Upgrade `@​actions/tool-cache` from 2.0.1 to 2.0.2 by [`@​dependabot`](https://github.com/dependabot)[bot] in [actions/setup-python#1095](https://redirect.github.com/actions/setup-python/pull/1095)
>
> New Contributors
> ----------------
>
> * [`@​krystof-k`](https://github.com/krystof-k) made their first contribution in [actions/setup-python#787](https://redirect.github.com/actions/setup-python/pull/787)
> * [`@​cdce8p`](https://github.com/cdce8p) made their first contribution in [actions/setup-python#1110](https://redirect.github.com/actions/setup-python/pull/1110)
> * [`@​aradkdj`](https://github.com/aradkdj) made their first contribution in [actions/setup-python#1067](https://redirect.github.com/actions/setup-python/pull/1067)
>
> **Full Changelog**: <actions/setup-python@v5...v6.0.0>


Commits

* [`e797f83`](actions/setup-python@e797f83) Upgrade to node 24 ([#1164](https://redirect.github.com/actions/setup-python/issues/1164))
* [`3d1e2d2`](actions/setup-python@3d1e2d2) Revert "Enhance cache-dependency-path handling to support files outside the w...
* [`65b0712`](actions/setup-python@65b0712) Clarify pythonLocation behavior for PyPy and GraalPy in environment variables...
* [`5b668cf`](actions/setup-python@5b668cf) Bump actions/checkout from 4 to 5 ([#1181](https://redirect.github.com/actions/setup-python/issues/1181))
* [`f62a0e2`](actions/setup-python@f62a0e2) Change missing cache directory error to warning ([#1182](https://redirect.github.com/actions/setup-python/issues/1182))
* [`9322b3c`](actions/setup-python@9322b3c) Upgrade setuptools to 78.1.1 to fix path traversal vulnerability in PackageIn...
* [`fbeb884`](actions/setup-python@fbeb884) Bump form-data to fix critical vulnerabilities [#182](https://redirect.github.com/actions/setup-python/issues/182) & [#183](https://redirect.github.com/actions/setup-python/issues/183) ([#1163](https://redirect.github.com/actions/setup-python/issues/1163))
* [`03bb615`](actions/setup-python@03bb615) Bump idna from 2.9 to 3.7 in /**tests**/data ([#843](https://redirect.github.com/actions/setup-python/issues/843))
* [`36da51d`](actions/setup-python@36da51d) Add version parsing from Pipfile ([#1067](https://redirect.github.com/actions/setup-python/issues/1067))
* [`3c6f142`](actions/setup-python@3c6f142) update documentation ([#1156](https://redirect.github.com/actions/setup-python/issues/1156))
* Additional commits viewable in [compare view](actions/setup-python@a26af69...e797f83)
  
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=actions/setup-python&package-manager=github\_actions&previous-version=5.6.0&new-version=6.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
mergify bot added a commit to robfrank/linklift that referenced this pull request Sep 8, 2025
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.6.0 to 6.0.0.
Release notes

*Sourced from [actions/setup-python's releases](https://github.com/actions/setup-python/releases).*

> v6.0.0
> ------
>
> What's Changed
> --------------
>
> ### Breaking Changes
>
> * Upgrade to node 24 by [`@​salmanmkc`](https://github.com/salmanmkc) in [actions/setup-python#1164](https://redirect.github.com/actions/setup-python/pull/1164)
>
> Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. [See Release Notes](https://github.com/actions/runner/releases/tag/v2.327.1)
>
> ### Enhancements:
>
> * Add support for `pip-version` by [`@​priyagupta108`](https://github.com/priyagupta108) in [actions/setup-python#1129](https://redirect.github.com/actions/setup-python/pull/1129)
> * Enhance reading from .python-version by [`@​krystof-k`](https://github.com/krystof-k) in [actions/setup-python#787](https://redirect.github.com/actions/setup-python/pull/787)
> * Add version parsing from Pipfile by [`@​aradkdj`](https://github.com/aradkdj) in [actions/setup-python#1067](https://redirect.github.com/actions/setup-python/pull/1067)
>
> ### Bug fixes:
>
> * Clarify pythonLocation behaviour for PyPy and GraalPy in environment variables by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1183](https://redirect.github.com/actions/setup-python/pull/1183)
> * Change missing cache directory error to warning by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1182](https://redirect.github.com/actions/setup-python/pull/1182)
> * Add Architecture-Specific PATH Management for Python with --user Flag on Windows by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1122](https://redirect.github.com/actions/setup-python/pull/1122)
> * Include python version in PyPy python-version output by [`@​cdce8p`](https://github.com/cdce8p) in [actions/setup-python#1110](https://redirect.github.com/actions/setup-python/pull/1110)
> * Update docs: clarification on pip authentication with setup-python by [`@​priya-kinthali`](https://github.com/priya-kinthali) in [actions/setup-python#1156](https://redirect.github.com/actions/setup-python/pull/1156)
>
> ### Dependency updates:
>
> * Upgrade idna from 2.9 to 3.7 in /**tests**/data by [`@​dependabot`](https://github.com/dependabot)[bot] in [actions/setup-python#843](https://redirect.github.com/actions/setup-python/pull/843)
> * Upgrade form-data to fix critical vulnerabilities [#182](https://redirect.github.com/actions/setup-python/issues/182) & [#183](https://redirect.github.com/actions/setup-python/issues/183) by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1163](https://redirect.github.com/actions/setup-python/pull/1163)
> * Upgrade setuptools to 78.1.1 to fix path traversal vulnerability in PackageIndex.download by [`@​aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-python#1165](https://redirect.github.com/actions/setup-python/pull/1165)
> * Upgrade actions/checkout from 4 to 5 by [`@​dependabot`](https://github.com/dependabot)[bot] in [actions/setup-python#1181](https://redirect.github.com/actions/setup-python/pull/1181)
> * Upgrade `@​actions/tool-cache` from 2.0.1 to 2.0.2 by [`@​dependabot`](https://github.com/dependabot)[bot] in [actions/setup-python#1095](https://redirect.github.com/actions/setup-python/pull/1095)
>
> New Contributors
> ----------------
>
> * [`@​krystof-k`](https://github.com/krystof-k) made their first contribution in [actions/setup-python#787](https://redirect.github.com/actions/setup-python/pull/787)
> * [`@​cdce8p`](https://github.com/cdce8p) made their first contribution in [actions/setup-python#1110](https://redirect.github.com/actions/setup-python/pull/1110)
> * [`@​aradkdj`](https://github.com/aradkdj) made their first contribution in [actions/setup-python#1067](https://redirect.github.com/actions/setup-python/pull/1067)
>
> **Full Changelog**: <actions/setup-python@v5...v6.0.0>


Commits

* [`e797f83`](actions/setup-python@e797f83) Upgrade to node 24 ([#1164](https://redirect.github.com/actions/setup-python/issues/1164))
* [`3d1e2d2`](actions/setup-python@3d1e2d2) Revert "Enhance cache-dependency-path handling to support files outside the w...
* [`65b0712`](actions/setup-python@65b0712) Clarify pythonLocation behavior for PyPy and GraalPy in environment variables...
* [`5b668cf`](actions/setup-python@5b668cf) Bump actions/checkout from 4 to 5 ([#1181](https://redirect.github.com/actions/setup-python/issues/1181))
* [`f62a0e2`](actions/setup-python@f62a0e2) Change missing cache directory error to warning ([#1182](https://redirect.github.com/actions/setup-python/issues/1182))
* [`9322b3c`](actions/setup-python@9322b3c) Upgrade setuptools to 78.1.1 to fix path traversal vulnerability in PackageIn...
* [`fbeb884`](actions/setup-python@fbeb884) Bump form-data to fix critical vulnerabilities [#182](https://redirect.github.com/actions/setup-python/issues/182) & [#183](https://redirect.github.com/actions/setup-python/issues/183) ([#1163](https://redirect.github.com/actions/setup-python/issues/1163))
* [`03bb615`](actions/setup-python@03bb615) Bump idna from 2.9 to 3.7 in /**tests**/data ([#843](https://redirect.github.com/actions/setup-python/issues/843))
* [`36da51d`](actions/setup-python@36da51d) Add version parsing from Pipfile ([#1067](https://redirect.github.com/actions/setup-python/issues/1067))
* [`3c6f142`](actions/setup-python@3c6f142) update documentation ([#1156](https://redirect.github.com/actions/setup-python/issues/1156))
* Additional commits viewable in [compare view](actions/setup-python@a26af69...e797f83)
  
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=actions/setup-python&package-manager=github\_actions&previous-version=5.6.0&new-version=6.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants