chore(ci): bump actions/github-script from 7.1.0 to 9.0.0#37
Conversation
Bumps [actions/github-script](https://github.com/actions/github-script) from 7.1.0 to 9.0.0. - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@f28e40c...3a2844b) --- updated-dependencies: - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Jerry-Xin
left a comment
There was a problem hiding this comment.
Relevance gate passed: this PR updates reusable GitHub Actions automation owned by the Mininglamp-OSS/.github project.
✅ Highlights
- 🔵 Suggestion: No action needed. The changed
actions/github-scriptusages are pinned to the v9.0.0 commit in.github/workflows/issue-welcome.yml:19,.github/workflows/reusable-pr-contributor-welcome.yml:41, and.github/workflows/reusable-pr-labeler.yml:31. - ✅ The embedded scripts use the standard injected
githubclient andgithub.restAPIs, with norequire('@actions/github')usage and noconst/let getOctokitredeclaration that would break on v9. - ✅ Runner compatibility looks acceptable: the workflows use GitHub-hosted
ubuntu-latestorubuntu-24.04, so the Node 24 runner requirement from the v8/v9 upgrade should be satisfied.
No blocking bugs, security regressions, or architectural issues found in this dependency bump.
lml2468
left a comment
There was a problem hiding this comment.
Review: PR #37 — chore(ci): bump actions/github-script from 7.1.0 to 9.0.0
Verdict: Safe Dependabot bump. LGTM ✅
Verification
- ✅ SHA
3a2844b7e9c422d3c10d287c895573f7108da1b3confirmed — annotated tagv9.0.0→ commit matches - ✅ CI green (actionlint + tab check pass)
- ✅ All 3 workflows updated consistently:
issue-welcome.yml,reusable-pr-contributor-welcome.yml,reusable-pr-labeler.yml
Analysis
v7 → v9 is a major version jump. The workflows use standard github-script APIs (github.rest.*, github.request(), github.paginate(), context, core) — these are stable Octokit interfaces that actions/github-script surfaces, not version-specific APIs. The inline scripts don't use any deprecated features.
No blocking or non-blocking findings.
Reviewer: 齐静春 (qijingchun) — independent cross-review
Bumps actions/github-script from 7.1.0 to 9.0.0.
Release notes
Sourced from actions/github-script's releases.
Commits
3a2844bMerge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...ca10bbdfix: use@octokit/core/types import for v7 compatibility86e48e2merge: incorporate main branch changesc108472chore: rebuild dist for v9 upgrade and getOctokit factoryafff112Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...ff8117eci: fix user-agent test to handle orchestration ID81c6b78ci: use deployment: false to suppress deployment noise from integration tests3953cafdocs: update README examples from@v8to@v9, add getOctokit docs and v9 brea...c17d55bci: add getOctokit integration test joba047196test: add getOctokit integration tests via callAsyncFunctionDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)