Guide

GitHub Actions Versions Report

Updated: 2026-08-14

Every action is pinned by commit SHA, never by tag: a tag is mutable and can be moved onto different code after review. The trailing comment records which release that SHA is, down to the patch — a bare # v6 next to a SHA cannot be checked against anything, and one of them had drifted a whole major behind what the comment claimed.

Current Versions in CI/CD Pipeline

.github/workflows/ci.yml

Action Version Node.js Notes
actions/checkout v7.0.1 24
actions/setup-go v7.0.0 24 ESM runtime, @actions/cache 6.2
actions/upload-artifact v7.0.1 24
actions/download-artifact v8.0.1 24
codecov/codecov-action v7.0.0 24
golangci/golangci-lint-action v9.3.0 24 linter itself resolved as latest
softprops/action-gh-release v3.0.2 24 v3 = Node 24 runtime; inputs unchanged from v2
docker/build-push-action v7.3.0 24
docker/setup-buildx-action v4.2.0 24
docker/login-action v4.6.0 24
docker/metadata-action v6.2.0 24
snapcore/action-build v1 24 (forced) FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true
snapcore/action-publish v1 24 (forced) FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true

.github/workflows/docs-site.yml

Action Version Node.js Notes
actions/checkout v7.0.1 24
spagu/ssg v1.8.32 Docker the site generator, pinned to its newest release

Toolchain pinned in the workflow

Tool Version Where
Go 1.26.6 go-version: in every job, and go 1.26.6 in go.mod
gosec v2.28.0 tool directive in tools/go.mod, every transitive version fixed by tools/go.sum
golangci-lint latest version: latest in the lint job

gosec lives in a separate tools/ module rather than in the project's own go.mod: it is built with go -C tools build, so the scanner and everything beneath it come from a lock file, while its dependency tree — gRPC, OpenTelemetry, a handful of cloud SDKs — stays out of wpexporter's. go install pkg@version would pin only gosec itself and re-resolve the rest on every run.

Upgrading it is two commands:

1go -C tools get -tool github.com/securego/gosec/v2/cmd/gosec@vX.Y.Z
2make sec        # builds the pinned scanner and runs it exactly as CI does

Checking for updates

scripts/check-actions-dynamic-v2.sh reports what is available. To verify a pin by hand — resolve the SHA the workflow uses and compare it to the tag the comment claims:

1# Which release is this SHA?
2gh api "repos/actions/checkout/tags?per_page=100" --paginate \
3  --jq '.[] | select(.commit.sha=="<SHA>") | .name'
4
5# What is the newest release, and which commit does it point at?
6gh api repos/actions/checkout/releases/latest --jq .tag_name
7gh api repos/actions/checkout/git/ref/tags/v7.0.1 --jq .object.sha

Annotated tags answer with a tag object rather than a commit; dereference it with gh api repos/<owner>/<repo>/git/tags/<sha> --jq .object.sha.

Note: All actions run on the Node.js 24 runtime. Node.js 20 leaves the GitHub Actions runners on September 16th, 2026.