Skip to content

[scan:deps] migrate GitHub Actions setup-python v6 → v7 across all 9 workflow call sites #490

Description

@claude

Role

You are a senior backend engineer working in this project's codebase, following
its existing conventions (TDD via stay-green, check-all.sh gates, ≥90% line /
≥80% branch backend coverage, zero lint/type suppressions). For this CI-only
change the deliverable is a workflow update verified by the actions linters that
pre-commit run --all-files already runs.

Goal

Migrate every actions/setup-python reference in .github/workflows/ from v6 to
v7 in a single PR — including the SHA-pinned # v6.x call sites that Dependabot
PR #489's tag bump does not touch — so all nine usages land on v7 consistently
and CI stays green.

Context

  • File(s) — all nine actions/setup-python call sites:
    • .github/workflows/ci.yml:32, :85, :225, :281, :353 — uses: actions/setup-python@v6
    • .github/workflows/metrics.yml:22 — uses: actions/setup-python@v6
    • .github/workflows/_claude-scan.yml:80 — actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 (SHA-pinned)
    • .github/workflows/ralph-recap.yml:34 — actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (SHA-pinned)
    • .github/workflows/deslop.yml:97 — actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (SHA-pinned)
  • Scanned at commit: 4135ac8bd402b2a512fb1b3405a38bfd13bfddef — re-verify against HEAD before starting.
  • Evidence:
    • Dependabot PR ci(deps): bump actions/setup-python from 6 to 7 #489 — ci(deps): bump actions/setup-python from 6 to 7 (real, open). This is the concrete major version delta (6 → 7).
    • v7.0.0 release notes list exactly one consumer-facing breaking change:
      "Remove the pip-install input" (Remove the pip-install input actions/setup-python#1336). Other v7
      changes are internal (ESM migration, dependency bumps) or non-breaking
      behavior tweaks (stderr classified as warnings, manifest-fetch retry).
    • Breaking change verified inapplicable here: grep -rn "pip-install" .github/workflows/ returns none. Every call site uses only
      python-version and cache: 'pip', both fully supported in v7. Hence this
      major carries no breaking risk for this repo → labeled P2, not the
      P1 that a breaking major would warrant.
    • Cross-PR value: Dependabot ci(deps): bump actions/setup-python from 6 to 7 #489 flips @v6 → @v7 tags but the three
      SHA-pinned call sites (_claude-scan.yml, ralph-recap.yml, deslop.yml)
      are pinned to v6 commit SHAs and will be left on v6 by a tag-only bump. This
      issue unifies all nine references — the work per-PR automation cannot do.
  • Related: Dependabot PR ci(deps): bump actions/setup-python from 6 to 7 #489 (setup-python 6→7); sibling patch PR ci(deps): bump actions/checkout from 7.0.0 to 7.0.1 in the actions-patch-minor group across 1 directory #488
    (actions/checkout 7.0.0→7.0.1) is a single grouped patch handled by
    Dependabot's own actions-patch-minor group and per-PR automation — not
    batched here.

Output Format

A single PR that:

  1. Updates all nine actions/setup-python references to v7 — either @v7 or a
    v7 commit SHA pinned with a # v7.x.y comment, matching each file's existing
    pinning style (tag-pinned files → @v7; SHA-pinned files → v7 SHA + comment).
  2. Leaves every with: block unchanged (python-version, cache: 'pip' are
    still valid in v7).
  3. Passes pre-commit run --all-files (actionlint / workflow validation hooks)
    and keeps CI green across all jobs.
  4. References this issue with "Closes #".

Examples

Tag-pinned call site (e.g. ci.yml:32):

# before
- uses: actions/setup-python@v6
  with:
    python-version: ${{ env.PYTHON_VERSION }}
    cache: 'pip'
# after
- uses: actions/setup-python@v7
  with:
    python-version: ${{ env.PYTHON_VERSION }}
    cache: 'pip'

SHA-pinned call site (e.g. _claude-scan.yml:80) — update SHA and comment
to the resolved v7 release:

# before
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405  # v6.2.0
# after
- uses: actions/setup-python@<v7-release-sha>  # v7.0.0

Constraints

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Quality: refactor, coverage, perf, a11yagent-readyFully specified; Ralph may pick upscan:depsFiled by the deps maintenance scan

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions