You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[scan:deps] migrate GitHub Actions setup-python v6 → v7 across all 9 workflow call sites #490
You are a senior backend engineer working in this project's codebase, following
its existing conventions (TDD via stay-green, check-all.sh gates, ≥90% line /
≥80% branch backend coverage, zero lint/type suppressions). For this CI-only
change the deliverable is a workflow update verified by the actions linters that pre-commit run --all-files already runs.
Goal
Migrate every actions/setup-python reference in .github/workflows/ from v6 to
v7 in a single PR — including the SHA-pinned # v6.x call sites that Dependabot
PR #489's tag bump does not touch — so all nine usages land on v7 consistently
and CI stays green.
Context
File(s) — all nine actions/setup-python call sites:
v7.0.0 release notes list exactly one consumer-facing breaking change: "Remove the pip-install input" (Remove the pip-install input actions/setup-python#1336). Other v7
changes are internal (ESM migration, dependency bumps) or non-breaking
behavior tweaks (stderr classified as warnings, manifest-fetch retry).
Breaking change verified inapplicable here:grep -rn "pip-install" .github/workflows/ returns none. Every call site uses only python-version and cache: 'pip', both fully supported in v7. Hence this
major carries no breaking risk for this repo → labeled P2, not the
P1 that a breaking major would warrant.
Cross-PR value: Dependabot ci(deps): bump actions/setup-python from 6 to 7 #489 flips @v6 → @v7 tags but the three
SHA-pinned call sites (_claude-scan.yml, ralph-recap.yml, deslop.yml)
are pinned to v6 commit SHAs and will be left on v6 by a tag-only bump. This
issue unifies all nine references — the work per-PR automation cannot do.
Updates all nine actions/setup-python references to v7 — either @v7 or a
v7 commit SHA pinned with a # v7.x.y comment, matching each file's existing
pinning style (tag-pinned files → @v7; SHA-pinned files → v7 SHA + comment).
Leaves every with: block unchanged (python-version, cache: 'pip' are
still valid in v7).
Passes pre-commit run --all-files (actionlint / workflow validation hooks)
and keeps CI green across all jobs.
References this issue with "Closes #".
Examples
Tag-pinned call site (e.g. ci.yml:32):
# before
- uses: actions/setup-python@v6with:
python-version: ${{ env.PYTHON_VERSION }}cache: 'pip'# after
- uses: actions/setup-python@v7with:
python-version: ${{ env.PYTHON_VERSION }}cache: 'pip'
SHA-pinned call site (e.g. _claude-scan.yml:80) — update SHA and comment
to the resolved v7 release:
# before
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0# after
- uses: actions/setup-python@<v7-release-sha> # v7.0.0
Constraints
Do not change with: inputs or any workflow logic — this is a version bump only.
No lint/type suppressions (max-quality-no-shortcuts): fix root causes.
Preserve each file's pinning convention (tag vs. SHA-with-comment); do not
convert one style to the other.
If the finding no longer reproduces at HEAD (e.g. ci(deps): bump actions/setup-python from 6 to 7 #489 already merged and all
nine sites are on v7), close this issue with a comment explaining what changed
instead of forcing a PR.
Role
You are a senior backend engineer working in this project's codebase, following
its existing conventions (TDD via stay-green,
check-all.shgates, ≥90% line /≥80% branch backend coverage, zero lint/type suppressions). For this CI-only
change the deliverable is a workflow update verified by the actions linters that
pre-commit run --all-filesalready runs.Goal
Migrate every
actions/setup-pythonreference in.github/workflows/from v6 tov7 in a single PR — including the SHA-pinned
# v6.xcall sites that DependabotPR #489's tag bump does not touch — so all nine usages land on v7 consistently
and CI stays green.
Context
actions/setup-pythoncall sites:.github/workflows/ci.yml:32,:85,:225,:281,:353—uses: actions/setup-python@v6.github/workflows/metrics.yml:22—uses: actions/setup-python@v6.github/workflows/_claude-scan.yml:80—actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0(SHA-pinned).github/workflows/ralph-recap.yml:34—actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0(SHA-pinned).github/workflows/deslop.yml:97—actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0(SHA-pinned)4135ac8bd402b2a512fb1b3405a38bfd13bfddef— re-verify against HEAD before starting.ci(deps): bump actions/setup-python from 6 to 7(real, open). This is the concrete major version delta (6 → 7)."Remove the pip-install input" (Remove the pip-install input actions/setup-python#1336). Other v7
changes are internal (ESM migration, dependency bumps) or non-breaking
behavior tweaks (stderr classified as warnings, manifest-fetch retry).
grep -rn "pip-install" .github/workflows/returns none. Every call site uses onlypython-versionandcache: 'pip', both fully supported in v7. Hence thismajor carries no breaking risk for this repo → labeled P2, not the
P1 that a breaking major would warrant.
@v6→@v7tags but the threeSHA-pinned call sites (
_claude-scan.yml,ralph-recap.yml,deslop.yml)are pinned to v6 commit SHAs and will be left on v6 by a tag-only bump. This
issue unifies all nine references — the work per-PR automation cannot do.
(actions/checkout 7.0.0→7.0.1) is a single grouped patch handled by
Dependabot's own
actions-patch-minorgroup and per-PR automation — notbatched here.
Output Format
A single PR that:
actions/setup-pythonreferences to v7 — either@v7or av7 commit SHA pinned with a
# v7.x.ycomment, matching each file's existingpinning style (tag-pinned files →
@v7; SHA-pinned files → v7 SHA + comment).with:block unchanged (python-version,cache: 'pip'arestill valid in v7).
pre-commit run --all-files(actionlint / workflow validation hooks)and keeps CI green across all jobs.
Examples
Tag-pinned call site (e.g.
ci.yml:32):SHA-pinned call site (e.g.
_claude-scan.yml:80) — update SHA and commentto the resolved v7 release:
Constraints
with:inputs or any workflow logic — this is a version bump only.actions/setup-pythononly. Do not fold in theactions/checkoutpatch(ci(deps): bump actions/checkout from 7.0.0 to 7.0.1 in the actions-patch-minor group across 1 directory #488) or any other action bump — file follow-ups for adjacent work.
convert one style to the other.
nine sites are on v7), close this issue with a comment explaining what changed
instead of forcing a PR.