Skip to content

Update CI to the latest actions and supported Node.js versions - #167

Open
thoda-dev wants to merge 8 commits into
mailtrap:mainfrom
thoda-dev:ci-update-to-latest
Open

thoda-dev wants to merge 8 commits into
mailtrap:mainfrom
thoda-dev:ci-update-to-latest

Conversation

@thoda-dev

@thoda-dev thoda-dev commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

Follow-up to the CI discussion in #161: Node.js 20 is being removed from GitHub Actions runners, codeql-action v3 is deprecated, @izikaj asked for CI on Node.js 24, and @oshchyhol pointed out that CI tested neither the versions engines promises nor nodemailer 9. I said I'd add a nodemailer 9 job, so it's here.

Changes

  • Actions: checkout v2/v4 → v7, setup-node v3/v4 → v7, github-script v7 → v9, codeql-action v3 → v4. The old ones run on Node.js runtimes GitHub no longer supports. The breaking changes in these majors don't affect our workflows.
  • Node.js 24: .tool-versions goes from 20.20.2 (EOL since April 2026) to 24.21.0. The lint job now reads it through node-version-file, like the release workflow already did.
  • engines.node raised to >=22, README updated. In Nodemailer 10 support #161 I argued for keeping >=16.20.1. I changed my mind: every version below 22 is end-of-life, and keeping it meant promising versions CI doesn't test.
  • Node.js matrix: new test (Node.js 22 / 24 / 26) jobs.
  • nodemailer jobs: nodemailer 9 (with @types/nodemailer) and nodemailer 10. Each one type-checks the sources and runs the tests against that major, then type-checks a consumer project against the packed build, as CommonJS without esModuleInterop and as native ESM (nodenext). I checked that they fail on the commits before 0d42479 and 1a803cc, so they would have caught both type breaks found in Nodemailer 10 support #161.
  • Hardening: permissions: contents: read, superseded PR runs cancelled, job timeouts, persist-credentials: false where nothing is pushed. The release workflow passes the tag through env instead of interpolating it in scripts. I also removed the CodeQL template comments and the unused manual build step.

The required check names don't change (lint, Analyze (javascript-typescript)).

Impacts

  • Breaking for users on Node.js < 22: this should ship in a major release (v5.0.0 in Release v5.0.0 #166 would fit) and be mentioned in the release notes.
  • Contributors need Node.js 24 locally (.tool-versions).
  • The new jobs aren't required checks. Up to you whether to make them required.
  • 6 jobs per PR instead of 1, so more CI minutes.

How to test

  • All checks on this PR pass: lint, test (Node.js 22/24/26), nodemailer 9, nodemailer 10, CodeQL
  • The draft release workflow can only be checked on its next manual run

Images and GIFs

N/A


This is a proposal, not a final version. If some of these choices don't match what you want for the project (engines, the matrix, the extra jobs…), tell me and I'll adjust.

Summary by CodeRabbit

  • Compatibility
    • Node.js 22 or newer is now required.
    • Nodemailer versions 9 and 10 remain supported.
  • Quality Assurance
    • Added test coverage across Node.js 22, 24, and 26, and compatibility checks for Nodemailer 9 and 10, including CommonJS and native ESM usage.
  • Workflow Improvements
    • Updated automated workflows and added cancellation of in-progress pull request runs.

Update checkout and setup-node, whose Node.js 12/16 runtimes no longer run
on GitHub Actions. Move development and the lint job to Node.js 24 LTS, as
Node.js 20 reached end of life. Keep the lint job name, it is the required
check on main.
codeql-action v3 is deprecated. Drop the template comments and the unused
manual build step. The job name stays the same.
Pass the tag to scripts through env instead of interpolating it in the
script body, like the other steps already do.
Copilot AI lite review requested due to automatic review settings October 7, 2026 13:03
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b5970f38-dcff-4055-807e-bc5bee966ad3
📥 Commits

Reviewing files that changed from the base of the PR and between 0ef3fde and d0c17a3.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 315cc0aa-d81c-49b8-b77a-c1042a272e5a
📥 Commits

Reviewing files that changed from the base of the PR and between c4c1566 and 0ef3fde.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (6)
  • .github/workflows/codeql.yml
  • .github/workflows/draft-release.yml
  • .github/workflows/test.yml
  • .tool-versions
  • README.md
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The package now requires Node.js 22 or newer. The test workflow adds Node.js and Nodemailer compatibility checks. The CodeQL and draft-release workflows update action versions and workflow settings.

Changes

Node.js support and compatibility

Layer / File(s) Summary
Node.js runtime requirements
.tool-versions, package.json, README.md
The configured Node.js version changes to 24.21.0. The package minimum and README prerequisite change to Node.js 22; the Nodemailer note removes its separate Node.js 20 requirement.
Test workflow configuration
.github/workflows/test.yml
The workflow limits permissions, adds concurrency control, updates the lint job actions and Node.js selection, disables persisted checkout credentials, and sets a 15-minute timeout.
Runtime and Nodemailer test matrices
.github/workflows/test.yml, package.json
The workflow tests Node.js 22, 24, and 26, and checks Nodemailer 9 and 10. These checks type-check and test the package, then type-check packed CommonJS and native ESM consumer examples.

GitHub workflow updates

Layer / File(s) Summary
CodeQL workflow execution
.github/workflows/codeql.yml
The workflow adds concurrency control, uses Ubuntu for all analysis languages, upgrades checkout and CodeQL actions, and removes introductory comments and the manual-build placeholder.
Draft-release actions and tag handling
.github/workflows/draft-release.yml
The workflow upgrades checkout, Node.js setup, and GitHub Script actions. Selected steps read the tag from the TAG environment variable instead of interpolating it into JavaScript.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 0ef3f

No actionable issue remains from this review; the change is mergeable after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 0ef3f

The inspected changes narrow validation-job credentials and preserve release automation’s existing authority and sequencing. No introduced or worsened security concern was established. Risk remains low rather than minimal because the upgraded actions’ credential and failure behavior has not been independently verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The strongest declared write authority in these workflows remains repository content and pull-request mutation during manually dispatched release automation. CodeQL separately retains security-reporting authority. The new compatibility jobs do not declare release or deployment authority.

Trust Boundaries and Controls

  • observed — Pull-request validation executes repository code and installed dependencies under the test workflow’s read-only permission declaration. Release mutations remain in a separate manually dispatched workflow using GITHUB_TOKEN; release notes are passed as environment data and a body file rather than interpolated into shell source.

Resilience and Maintainability Implications

  • inferred — The release transition remains non-atomic: branch push and pull-request creation precede draft-release creation, with no cleanup step in this workflow. Interruption can leave partial repository state, and repetition can encounter existing branches or pull requests. The tag precheck and serialized execution mitigate some conflicts but do not provide transactional recovery. This limitation exists at the PR base and is not an introduced concern.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: updated CI actions and supported Node.js versions.
Description check ✅ Passed The description includes the required Motivation, Changes, and How to test sections. It also explains impacts and uses “N/A” for Images and GIFs.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It changes multiple CI workflows and the supported Node baseline, which needs a real GitHub Actions run/maintainer validation beyond static review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

This PR updates the repository’s supported Node.js baseline and modernizes GitHub Actions workflows to run CI across currently supported Node versions, including dedicated compatibility checks for Nodemailer 9 and 10.

Changes:

  • Raise the package’s supported Node.js range (engines.node) to >=22 and update local toolchain to Node 24 via .tool-versions.
  • Modernize CI workflows (actions majors, permissions hardening, concurrency, timeouts) and add a Node.js version matrix job.
  • Add Nodemailer-major CI jobs that validate both library source type-checking and consumer type-checking against the packed build.
File Description
README.md Documents the new Node.js baseline and updates the Nodemailer transport note.
package.json Raises engines.node to >=22.
.tool-versions Updates the local Node.js toolchain version to 24.21.0.
.github/​workflows/​test.yml Updates actions versions, adds concurrency/permissions/timeouts, adds Node matrix + Nodemailer compatibility jobs.
.github/​workflows/​draft-release.yml Updates actions versions and hardens tag handling by passing values via env.
.github/​workflows/​codeql.yml Updates CodeQL/action majors, adds concurrency, and simplifies the template.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants