Source profileQuality 82/100

github/awesome-copilot/skills/github-actions-runtime-upgrade-conventions/SKILL.md

github-actions-runtime-upgrade-conventions

Upgrade GitHub Actions to supported runtimes by selecting safe action versions, preserving workflow behavior, and validating post-upgrade execution.

Source repository stars
37,126
Declared platforms
0
Static risk flags
0
Last source update
2026-07-28
Source checked
2026-07-28

Decision brief

What it does—and where it fits

Use this skill when editing GitHub Actions workflows to address deprecation warnings about action runtimes (for example Node.js runtime migrations).

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/github/awesome-copilot --skill "skills/github-actions-runtime-upgrade-conventions"
    Safe inspection promptEditorial

    Inspect the Agent Skill "github-actions-runtime-upgrade-conventions" from https://github.com/github/awesome-copilot/blob/9933dcad5be5caeb288cebcd370eeeb2fc2f1685/skills/github-actions-runtime-upgrade-conventions/SKILL.md at commit 9933dcad5be5caeb288cebcd370eeeb2fc2f1685. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      Verification Checklist

      After changing action versions:

      Ensure all edited workflows still parse and keep the same triggers/permissions unless intentionally changed.Run the affected workflows (or equivalent local build/test commands) and confirm the upgraded steps complete successfully.Confirm release/signing/artifact steps still produce expected outputs where applicable.
    2. 02

      Use This Skill When

      Workflow logs report an action is running on a deprecated runtime.

      Workflow logs report an action is running on a deprecated runtime.You are upgrading action versions in .github/workflows/.yml or .github/workflows/.yaml.You need to keep existing workflow behavior while modernizing action dependencies.
    3. 03

      Upgrade Rules

      Prefer upgrading to the latest stable major version of each action that is compatible with the workflow.

      Prefer upgrading to the latest stable major version of each action that is compatible with the workflow.Prefer immutable pins: resolve the target release to a full commit SHA and use that SHA in uses:.Do not pin to mutable tags or branches (for example @v4 or @main) in final recommendations.
    4. 04

      Actions We Track in This Repo

      Prioritize runtime review for these groups when warnings appear:

      Any first-party action under actions/Especially setup actions under actions/setup- (for example setup-node, setup-python, setup-dotnet)Any other action explicitly named by the runtime deprecation warning in workflow logs

    Permission review

    Static risk signals and limitations

    No configured static risk pattern was detected

    This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score82/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars37,126SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    github/awesome-copilot
    Skill path
    skills/github-actions-runtime-upgrade-conventions/SKILL.md
    Commit
    9933dcad5be5caeb288cebcd370eeeb2fc2f1685
    License
    MIT
    Collected
    2026-07-28
    Default branch
    main
    View the original SKILL.md

    GitHub Actions Runtime Upgrade Conventions

    Use this skill when editing GitHub Actions workflows to address deprecation warnings about action runtimes (for example Node.js runtime migrations).

    Use This Skill When

    • Workflow logs report an action is running on a deprecated runtime.
    • You are upgrading action versions in .github/workflows/*.yml or .github/workflows/*.yaml.
    • You need to keep existing workflow behavior while modernizing action dependencies.

    Upgrade Rules

    • Prefer upgrading to the latest stable major version of each action that is compatible with the workflow.
    • Prefer immutable pins: resolve the target release to a full commit SHA and use that SHA in uses:.
    • Do not pin to mutable tags or branches (for example @v4 or @main) in final recommendations.
    • Upgrade one action at a time per commit (or one tightly related group) so failures are easy to isolate.
    • Keep existing workflow behavior unchanged while upgrading runtime/dependency actions.

    Actions We Track in This Repo

    Prioritize runtime review for these groups when warnings appear:

    • Any first-party action under actions/*
    • Especially setup actions under actions/setup-* (for example setup-node, setup-python, setup-dotnet)
    • Any other action explicitly named by the runtime deprecation warning in workflow logs

    Pinning Pattern

    steps:
      - uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608 # v4.3.1
      - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.4
    

    When recommending upgrades, identify the latest compatible release first, then use the corresponding commit SHA with an optional version comment.

    Verification Checklist

    After changing action versions:

    1. Ensure all edited workflows still parse and keep the same triggers/permissions unless intentionally changed.
    2. Run the affected workflows (or equivalent local build/test commands) and confirm the upgraded steps complete successfully.
    3. Confirm release/signing/artifact steps still produce expected outputs where applicable.
    4. Check workflow run logs for any new deprecation warnings or runtime migration notes.

    PR Notes

    Include in the PR summary:

    • Which actions were upgraded (from -> to).
    • Whether any action could not move to a new major and why.
    • Which workflows were re-run to validate the change.

    How This Complements Dependabot

    Dependabot can automate many updates, but this skill still helps when:

    • Dependabot is not enabled for workflows in a repository.
    • Runtime warnings appear before an automated update is available.
    • A workflow needs behavior-preserving validation after the action bump.

    Alternatives

    Compare before choosing