Skip to content

deps: Update actions/github-script action to v9#140

Merged
ANcpLua merged 3 commits into
mainfrom
renovate/actions-github-script-9.x
May 18, 2026
Merged

deps: Update actions/github-script action to v9#140
ANcpLua merged 3 commits into
mainfrom
renovate/actions-github-script-9.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 18, 2026

This PR contains the following updates:

Package Type Update Change
actions/github-script action major v7v9

Release Notes

actions/github-script (actions/github-script)

v9.0.0

Compare Source

New features:

  • getOctokit factory function — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See Creating additional clients with getOctokit for details and examples.
  • Orchestration ID in user-agent — The ACTIONS_ORCHESTRATION_ID environment variable is automatically appended to the user-agent string for request tracing.

Breaking changes:

  • require('@​actions/github') no longer works in scripts. The upgrade to @actions/github v9 (ESM-only) means require('@​actions/github') will fail at runtime. If you previously used patterns like const { getOctokit } = require('@​actions/github') to create secondary clients, use the new injected getOctokit function instead — it's available directly in the script context with no imports needed.
  • getOctokit is now an injected function parameter. Scripts that declare const getOctokit = ... or let getOctokit = ... will get a SyntaxError because JavaScript does not allow const/let redeclaration of function parameters. Use the injected getOctokit directly, or use var getOctokit = ... if you need to redeclare it.
  • If your script accesses other @actions/github internals beyond the standard github/octokit client, you may need to update those references for v9 compatibility.
What's Changed
New Contributors

Full Changelog: actions/github-script@v8.0.0...v9.0.0

v9

Compare Source

v8.0.0

Compare Source

v8: .0.0

Compare Source

What's Changed
⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

New Contributors

Full Changelog: actions/github-script@v7.1.0...v8.0.0

v7.1.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v7...v7.1.0

v7.0.1

Compare Source

What's Changed

Full Changelog: actions/github-script@v7.0.0...v7.0.1


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file major labels May 18, 2026
@codacy-production
Copy link
Copy Markdown

codacy-production Bot commented May 18, 2026

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

Copy link
Copy Markdown

@codacy-production codacy-production Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

The pull request aims to update the actions/github-script dependency to version v9. However, the official action has only released versions up to v7. Referencing a non-existent version or an unverified commit hash introduces high risk of workflow failure and potential security concerns. Furthermore, the PR does not address or verify compatibility with the breaking changes typical of major version updates (e.g., Node.js runtime shifts or API changes). This update should be halted until the version reference is corrected to a stable, official release and verified against the existing script logic.

About this PR

  • Major version updates for actions/github-script often involve breaking changes, such as the transition to ESM or updates to the Node.js runtime (Node 24). There are no automated tests or verification steps provided to ensure the current script functionality in triage-bot.yml remains compatible with these changes.

Test suggestions

  • Verify the Triage Bot script executes successfully without syntax errors related to getOctokit redeclaration or require usage.
  • Confirm github.graphql calls and core utilities function correctly in the v9 runtime (Node 24).
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify the Triage Bot script executes successfully without syntax errors related to `getOctokit` redeclaration or `require` usage.
2. Confirm `github.graphql` calls and `core` utilities function correctly in the `v9` runtime (Node 24).

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

steps:
- name: Triage unresolved review threads
uses: actions/github-script@v7
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 HIGH RISK

The actions/github-script action has not released a version 9 (the current latest stable version is v7). Please verify the version number and ensure the commit hash corresponds to an official release of actions/github-script to avoid potential security risks or execution failures.

@renovate renovate Bot force-pushed the renovate/actions-github-script-9.x branch from a3a6611 to 7c3d4fb Compare May 18, 2026 18:11
@github-actions
Copy link
Copy Markdown

@coderabbitai autofix

@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented May 18, 2026

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@github-actions
Copy link
Copy Markdown

@coderabbitai autofix

@ANcpLua ANcpLua merged commit 22443c8 into main May 18, 2026
6 of 7 checks passed
@ANcpLua ANcpLua deleted the renovate/actions-github-script-9.x branch May 18, 2026 22:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file major

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant