You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We need hackforla/automate-the-org's Add Update Label Weekly action to declare the node24 runtime instead of node20, because GitHub has deprecated Node 20 and is already force-running the action on Node 24. Every weekly run in devops, devops-security and incubator carries the deprecation annotation, and the forcing is transitional behaviour rather than a fix.
Action Items
Note the change lands in a different repository. The fix is in hackforla/automate-the-org, which is not on this board and carries none of our label axes, so this issue tracks the work and the PR goes there. Nothing in hackforla/devops is edited by this issue.
In gha-add-update-label-weekly/action.yml, change runs: using: 'node20' to using: 'node24'. Line 19 as of 2026-09-12; find it by using: if it has drifted.
Confirm this is still the only action.yml in that repository before assuming the change is complete — it was on both 2026-09-10 and 2026-09-12, so there is no second action to sweep, but a new one would need the same treatment.
Check whether dist/index.js needs rebuilding against Node 24, or whether the declaration change alone is sufficient. It is a bundled JS action, so the runtime declaration and the bundle are separate concerns; if the build pipeline pins a Node version, bump it in the same pass.
Cut a new v1.x release and move the floating v1 tag onto it.
Do not open PRs on the three consumer repos.devops, devops-security and incubator each call hackforla/automate-the-org/gha-add-update-label-weekly@v1 from their own .github/workflows/add-update-label-weekly.yml. All three float on @v1, so moving that tag propagates the fix to all three at once. Three consumer PRs would be redundant and would not make the fix land any sooner.
After the release, run one consumer's workflow by hand — gh workflow run add-update-label-weekly.yml -R hackforla/devops — and confirm the run's annotations no longer include "Node.js 20 is deprecated". The ATO workflow has workflow_dispatch, so this does not have to wait for the weekly schedule.
Confirm the same on a second consumer. That checks the floating tag actually resolving for every caller rather than one repo's result.
Resources/Instructions
The annotation, seen on real runs: "Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: hackforla/automate-the-org/gha-add-update-label-weekly@v1". Found 2026-09-10 while running the post-merge regression check for Delete the four orphaned files left behind by the old label automation #220.
A green run history is not evidence against this. The forced upgrade is GitHub's transition behaviour, so runs succeed today and will keep succeeding until the forcing stops. This is a countdown, not a breakage — check GitHub's current deprecation timeline when sizing the urgency.
Deliberately out of scope: the actions/create-github-app-token@v3app-id deprecation. The same runs carry a second annotation saying app-id is deprecated in favour of client-id. That line sits in each of the three consumer repos' own workflow files rather than in the action — but those files appear to have been vendored from automate-the-org in the first place, so whether a local fix would survive the next rollout is unconfirmed. Settle that before editing any of the three; this change does not fix it.
main and the v1 tag were the same commit as of 2026-09-10, and v1 resolved to v1.3.0, so what the three repos run today is what is on that repo's main.
Overview
We need
hackforla/automate-the-org's Add Update Label Weekly action to declare thenode24runtime instead ofnode20, because GitHub has deprecated Node 20 and is already force-running the action on Node 24. Every weekly run indevops,devops-securityandincubatorcarries the deprecation annotation, and the forcing is transitional behaviour rather than a fix.Action Items
hackforla/automate-the-org, which is not on this board and carries none of our label axes, so this issue tracks the work and the PR goes there. Nothing inhackforla/devopsis edited by this issue.gha-add-update-label-weekly/action.yml, changeruns: using: 'node20'tousing: 'node24'. Line 19 as of 2026-09-12; find it byusing:if it has drifted.action.ymlin that repository before assuming the change is complete — it was on both 2026-09-10 and 2026-09-12, so there is no second action to sweep, but a new one would need the same treatment.dist/index.jsneeds rebuilding against Node 24, or whether the declaration change alone is sufficient. It is a bundled JS action, so the runtime declaration and the bundle are separate concerns; if the build pipeline pins a Node version, bump it in the same pass.v1.xrelease and move the floatingv1tag onto it.devops,devops-securityandincubatoreach callhackforla/automate-the-org/gha-add-update-label-weekly@v1from their own.github/workflows/add-update-label-weekly.yml. All three float on@v1, so moving that tag propagates the fix to all three at once. Three consumer PRs would be redundant and would not make the fix land any sooner.gh workflow run add-update-label-weekly.yml -R hackforla/devops— and confirm the run's annotations no longer include "Node.js 20 is deprecated". The ATO workflow hasworkflow_dispatch, so this does not have to wait for the weekly schedule.Resources/Instructions
actions/create-github-app-token@v3app-iddeprecation. The same runs carry a second annotation sayingapp-idis deprecated in favour ofclient-id. That line sits in each of the three consumer repos' own workflow files rather than in the action — but those files appear to have been vendored from automate-the-org in the first place, so whether a local fix would survive the next rollout is unconfirmed. Settle that before editing any of the three; this change does not fix it.mainand thev1tag were the same commit as of 2026-09-10, andv1resolved tov1.3.0, so what the three repos run today is what is on that repo'smain.