Skip to content

Declare logger, refresh action pins, drop grunt tooling - #790

Merged
amjjbonvin merged 1 commit into
masterfrom
chore/deps-actions-cleanup
Sep 29, 2026
Merged

amjjbonvin merged 1 commit into
masterfrom
chore/deps-actions-cleanup

Conversation

@amjjbonvin

Copy link
Copy Markdown
Member

Backlog items 5, 6 and 7.

Item 5 — declare logger

Jekyll 4.4 requires logger but does not declare it, so it resolved from the
standard library and warned on every build. Ruby 3.5 removes it from the default
gems, at which point a bundled build without it is expected to fail rather than
warn.

Declared as gem "logger", "~> 1.6" → resolves to 1.7.0. Warning is gone.

Item 6 — refresh action pins

Action Was Now
actions/checkout v4 v7
actions/cache v4 v6
actions/configure-pages v4 v6
actions/deploy-pages v4 v5
actions/upload-pages-artifact v3 v5

checkout@v4 was the source of the Node 20 deprecation annotation on every run.

I checked the release notes before bumping: no breaking changes — the majors are
Node runtime upgrades and internal dependency bumps. upload-pages-artifact v5
uses upload-artifact v7 internally and deploy-pages v5 is its matching
generation, so the trio moves together. lychee-action and ruby/setup-ruby were
already current on their floating major tags.

Item 7 — drop the grunt tooling

Deleted package.json, Gruntfile.js, .jshintrc, plus the now-stale
Gruntfile.js / package.json entries in the _config.yml exclude list.

Nothing referenced them — no workflow, script or page, no package-lock.json, no
node_modules. assets/js/scripts.min.js is committed, so no build output is
lost.

This permanently closes the phantom grunt Dependabot alerts. The pin in
6e817a9 only raised the declared range; with the manifest gone there is nothing
left to scan, so the seven grunt-* dependencies still on open-ended ">1.3.0"
ranges cannot raise alerts either.

Worth noting the theme this tooling belonged to was already gone twice over:
#789 removed theme: minima, and package.json had long claimed to be
minimal-mistakes-theme — a third theme the site had not used in years.

Verification

One thing a PR cannot verify

The deploy workflow only runs on push to master, so this PR does not exercise
the upgraded Pages actions
. build.yml covers checkout@v7 and the Jekyll
build, but configure-pages@v6 / upload-pages-artifact@v5 / deploy-pages@v5
run for the first time on merge. They are a coordinated set with no documented
breaking changes, so the risk is low — but worth watching the deploy run, and the
live site, immediately after merging.

🤖 Generated with Claude Code

Backlog items 5, 6 and 7.

logger (item 5)
  Jekyll 4.4 requires logger but does not declare it, so it resolved from
  the standard library and warned on every build. Ruby 3.5 removes it from
  the default gems, at which point a bundled build without it is expected
  to fail rather than warn. Declared as `gem "logger", "~> 1.6"`, resolving
  to 1.7.0; the warning is gone.

GitHub Actions pins (item 6)
  checkout                v4 -> v7   (source of the Node 20 annotation)
  cache                   v4 -> v6
  configure-pages         v4 -> v6
  deploy-pages            v4 -> v5
  upload-pages-artifact   v3 -> v5

  Release notes for the Pages trio show no breaking changes; the majors are
  Node runtime upgrades and internal dependency bumps. upload-pages-artifact
  v5 uses upload-artifact v7 internally and deploy-pages v5 is its matching
  generation, so the three move together. lychee-action and setup-ruby were
  already current on their floating major tags.

grunt tooling (item 7)
  Delete package.json, Gruntfile.js and .jshintrc, and drop the now-stale
  Gruntfile.js and package.json entries from the _config.yml exclude list.
  Nothing referenced them: no workflow, script or page, no package-lock.json
  and no node_modules. assets/js/scripts.min.js is committed, so no build
  output is lost.

  This permanently closes the phantom grunt Dependabot alerts. The pin in
  6e817a9 only raised the declared range; with the manifest gone there is
  nothing left to scan, so the seven grunt-* dependencies still on
  open-ended ">1.3.0" ranges cannot raise alerts either.

Verified: the built site is byte-identical to the previous baseline across
all 1242 files, and the logger warning no longer appears. Only the @import
Sass deprecation remains, which is deferred by design.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@amjjbonvin
amjjbonvin merged commit 0584750 into master Sep 29, 2026
2 checks passed
@amjjbonvin
amjjbonvin deleted the chore/deps-actions-cleanup branch September 29, 2026 20:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant