github-actions-runtime-upgrade-conventions
Upgrade GitHub Actions to supported runtimes by selecting safe action versions, preserving workflow behavior, and validating post-upgrade execution.
Works with
--- name: github-actions-runtime-upgrade-conventions description: Upgrade GitHub Actions to supported runtimes by selecting safe action versions, preserving workflow behavior, and validating post-upgrade execution. license: MIT --- # GitHub Actions Runtime Upgrade Conventions Use this skill when editing GitHub Actions workflows to address deprecation warnings about action runtimes (for example Node.js runtime migrations). ## Use This Skill When - Workflow logs report an action is running on a deprecated runtime. - You are upgrading action versions in `.github/workflows/*.yml` or `.github/workflows/*.yaml`. - You need to keep existing workflow behavior while modernizing action dependencies. ## Upgrade Rules - Prefer upgrading to the latest stable **major** version of each action that is compatible with the workflow. - Prefer immutable pins: resolve the target release to a full commit SHA and use that SHA in `uses:`. - Do not pin to mutable tags or branches (for example `@v4` or `@main`) in final recommendations. - Upgrade one action at a time per commit (or one tightly related group) so failures are easy to isolate. - Keep existing workflow behavior unchanged while upgrading runtime/dependency actions. ## Actions We Track in This Repo Prioritize runtime review for these groups when warnings appear: - Any first-party action under `actions/*` - Especially setup actions under `actions/setup-*` (for example `setup-node`, `setup-python`, `setup-dotnet`) - Any other action explicitly named by the runtime deprecation warning in workflow logs ## Pinning Pattern ```yaml steps: - uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608 # v4.3.1 - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.4 ``` When recommending upgrades, identify the latest compatible release first, then use the corresponding commit SHA with an optional version comment. ## Verification Checklist After changing action versions: 1. Ensure all edited workflows still parse and keep the same triggers/permissions unless intentionally changed. 2. Run the affected workflows (or equivalent local build/test commands) and confirm the upgraded steps complete successfully. 3. Confirm release/signing/artifact steps still produce expected outputs where applicable. 4. Check workflow run logs for any new deprecation warnings or runtime migration notes. ## PR Notes Include in the PR summary: - Which actions were upgraded (from -> to). - Whether any action could not move to a new major and why. - Which workflows were re-run to validate the change. ## How This Complements Dependabot Dependabot can automate many updates, but this skill still helps when: - Dependabot is not enabled for workflows in a repository. - Runtime warnings appear before an automated update is available. - A workflow needs behavior-preserving validation after the action bump.
More Deployment & CI/CD skills
azure-enterprise-infra-planner
microsoft/azure-skills
Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.
azure-kubernetes-app-deploy
microsoft/azure-skills
Use when deploying an existing web application or API to an already-running Azure Kubernetes Service cluster. Detects the framework, generates a Dockerfile and Kubernetes manifests, validates against AKS Deployment Safeguards, and deploys with verification. WHEN: deploy app to AKS, deploy to existing AKS cluster, containerize app for Kubernetes, generate K8s manifests for Azure, set up CI/CD for AKS, my AKS deployment is failing safeguard checks, I have a Django/Express/Spring Boot app to run on AKS. DO NOT USE FOR: creating or provisioning an AKS cluster (use azure-kubernetes), assessing migration to AKS Automatic (use azure-kubernetes-automatic-readiness), or deploying to non-AKS targets like Web Apps, Container Apps, or Functions.
finetuning
microsoft/azure-skills
Fine-tune models on Microsoft Foundry using SFT (supervised), DPO (preference), or RFT (reinforcement with graders). Covers dataset preparation, training job submission, deployment, and evaluation. USE FOR: fine-tune, SFT, DPO, RFT, training data, grader, distillation, fine-tuned model, training job, large file upload, calibrate grader, deploy fine-tuned model, evaluate fine-tuned model. DO NOT USE FOR: general model deployment without fine-tuning (use deploy-model), agent creation (use agents), prompt optimization without training (use prompt-optimizer).

