Files
PaperClipAI/.github/workflows
dependabot[bot] c365a16e34 build(deps): bump actions/deploy-pages from 4.0.5 to 5.0.1 (#12963)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - The repository runs a weekly full-stack end-to-end campaign for the
runner, and that workflow publishes its merged dashboard to GitHub Pages
> - The publish flow has two actions: `actions/upload-pages-artifact`
packages the dashboard, and `actions/deploy-pages` deploys it
> - #12964 moved `actions/upload-pages-artifact` to version 5, and
`actions/deploy-pages` is still pinned to a version 4 commit
> - Version 4 of `actions/deploy-pages` runs on the Node.js 20 runtime,
and GitHub-hosted runners are moving actions to Node.js 24
> - This pull request moves the pin to the commit that upstream tags as
`v5.0.1`
> - The benefit is that both Pages actions are on the same major
version, the deploy step runs on Node.js 24, and the pin stays a commit
SHA

## Linked Issues or Issue Description

No public issue exists for this change. Refs #12964 (the matching
`actions/upload-pages-artifact` update, now merged) and Refs #12962
(another pinned GitHub Action update). They are related, and they are
not duplicates. The description below follows the enhancement template.

**What existing behavior does this improve?**

The weekly runner end-to-end workflow deploys its merged dashboard to
GitHub Pages. This change updates the action that performs that
deployment.

**Subsystem affected**

CI and release automation —
`.github/workflows/runner-full-stack-e2e.yml`.

**Current behavior**

The `pages` job uses `actions/deploy-pages` at commit
`d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e`, which runs on `node20`.

**Proposed behavior**

The `pages` job uses `actions/deploy-pages` at commit
`368f82528645a54fb793d4d04e342629a3f51346`, which upstream tags as
`v5.0.1` and which runs on `node24`. Version 5.0.1 also adds backoff and
jitter to the deployment status polling.

**Breaking changes**

None for this repository. The `action.yml` of both versions declares the
same six inputs (`token`, `timeout`, `error_count`,
`reporting_interval`, `artifact_name`, `preview`) with the same
defaults, and the same `page_url` output. The job passes `artifact_name`
only. The job runs on `ubuntu-latest`, which supports the `node24`
runtime.

## What Changed

- Change the pinned commit of `actions/deploy-pages` in
`.github/workflows/runner-full-stack-e2e.yml` from the version 4 commit
to `368f82528645a54fb793d4d04e342629a3f51346`, which upstream tags as
`v5.0.1`.

## Verification

- The pinned commit matches the upstream tag. `gh api
repos/actions/deploy-pages/git/ref/tags/v5.0.1 --jq .object.sha` returns
`368f82528645a54fb793d4d04e342629a3f51346`.
- The input and output contract stays the same. A comparison of
`action.yml` at the old pin and at the new pin shows identical inputs,
defaults and outputs. Only the runtime changes from `node20` to
`node24`.
- The repository CI suite passes on this branch after a rebase onto the
current base branch.
- One limit applies. The changed step runs only in the `Runner
Full-Stack E2E` workflow. That workflow starts on a weekly schedule and
on a manual dispatch, so no pull-request run exercises the step. A
maintainer can exercise it with a manual dispatch of that workflow, or
the next scheduled run exercises it.

## Risks

- Low risk, with one limit. The changed step does not run on a pull
request, so the pull-request checks do not prove the new action version
in this workflow.
- The runtime moves to Node.js 24. GitHub-hosted runners support it, and
this job uses a GitHub-hosted runner.
- The rollback is one commit. Restore the previous pinned commit of
`actions/deploy-pages`.

## Model Used

Dependabot generated this dependency update automatically, so no AI
model produced the code change. A maintainer wrote this description with
Claude Opus 5 (Anthropic, model id `claude-opus-5`, extended thinking,
tool use).

## Checklist

Three boxes stay unticked on purpose. This change pins one GitHub Action
version in one workflow file. No local test covers a pinned action
version, no new test applies, and no document refers to this pin.

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub #NNN / github.com/paperclipai/paperclip URLs)
- [x] My branch name describes the change (e.g. docs/..., fix/...) and
contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass
- [ ] I have added or updated tests where applicable
- [ ] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-06 14:32:16 -07:00
..