# CI on Github

**URL:** <https://discourse.julialang.org/t/ci-on-github/112471>\
**Category:** Tooling\
**Tags:** question\
**Created:** [April 3, 2024, 1:23pm UTC](https://discourse.julialang.org/t/ci-on-github/112471 "2024-04-03T13:23:49Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ufechner7](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ufechner7/32/51363_2.png) [@ufechner7](https://discourse.julialang.org/u/ufechner7)\
**Post date:** [April 3, 2024, 1:23pm UTC](https://discourse.julialang.org/t/ci-on-github/112471/1 "2024-04-03T13:23:49Z")

</div>

I get the following warnings when running a CI job on Github:

```julia
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/cache@4d4ae6ae148a43d0fd1eda1800170683e9882738, pyTooling/Actions/with-post-step@adef08d3bdef092282614f3b683897cefae82ee3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.

```

Any idea how to fix this?

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [April 3, 2024, 1:27pm UTC](https://discourse.julialang.org/t/ci-on-github/112471/2 "2024-04-03T13:27:28Z")

</div>

You might consider setting up Dependabot to automatically bump the versions of actions that you use.

For example, you could create a file in your repo named `.github/dependabot.yml` with the following contents:

```yaml
version: 2
updates:
  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "monthly"
    open-pull-requests-limit: 99
    labels:
      - "dependencies"
      - "github-actions"

```

---

<div class="post-metadata">

**Author:** ![ctkelley](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ctkelley/32/10684_2.png) [@ctkelley](https://discourse.julialang.org/u/ctkelley)\
**Post date:** [April 3, 2024, 1:51pm UTC](https://discourse.julialang.org/t/ci-on-github/112471/3 "2024-04-03T13:51:07Z")

</div>

You’re not alone. See [this thread](https://discourse.julialang.org/t/how-do-i-update-github-actions-to-node-js-20/110536/20).

---

<div class="post-metadata">

**Author:** ![ufechner7](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ufechner7/32/51363_2.png) [@ufechner7](https://discourse.julialang.org/u/ufechner7)\
**Post date:** [April 3, 2024, 2:20pm UTC](https://discourse.julialang.org/t/ci-on-github/112471/4 "2024-04-03T14:20:35Z")

</div>

Thanks for sharing `dependabot.yml` .

Two questions:

- are you sure it should go into the folder `.github` and not in the folder `.github/workflows` ?
- are you sure what you posted is complete? It does seam to be a valid workflow file, it is missing for example the tag `on`…

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [April 3, 2024, 2:22pm UTC](https://discourse.julialang.org/t/ci-on-github/112471/5 "2024-04-03T14:22:29Z")

</div>

> [@ufechner7](#):
>
> are you sure it should go into the folder `.github`

Yes. Per the GitHub docs:

> You must store this file in the `.github` directory of your repository in the default branch.

Source: [Configuration options for the dependabot.yml file - GitHub Docs](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#about-the-dependabotyml-file)

The `dependabot.yml` file is not a workflow file; it has a separate syntax.

---

<div class="post-metadata">

**Author:** ![ufechner7](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ufechner7/32/51363_2.png) [@ufechner7](https://discourse.julialang.org/u/ufechner7)\
**Post date:** [April 3, 2024, 2:22pm UTC](https://discourse.julialang.org/t/ci-on-github/112471/6 "2024-04-03T14:22:50Z")

</div>

Thank you!

---

<div class="post-metadata">

**Author:** ![ufechner7](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ufechner7/32/51363_2.png) [@ufechner7](https://discourse.julialang.org/u/ufechner7)\
**Post date:** [April 3, 2024, 2:38pm UTC](https://discourse.julialang.org/t/ci-on-github/112471/7 "2024-04-03T14:38:48Z")

</div>

I added dependabot, but I still get the same warnings:

> <https://github.com/ufechner7/KiteModels.jl/actions/runs/8540419315>

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [April 3, 2024, 4:06pm UTC](https://discourse.julialang.org/t/ci-on-github/112471/8 "2024-04-03T16:06:25Z")

</div>

I think the remaining steps are out of your hands now.

We need to update the versions of external actions used in the [`julia-actions/cache`](https://github.com/julia-actions/cache) action; specifically, we need to update the versions of `actions/cache` and `pyTooling/Actions`. Once we’ve done that, we’ll release a new version of `julia-actions/cache`.

Once the new release of `julia-actions/cache` has been been made, you should automatically receive a Dependabot PR the next time that Dependabot runs. You can either wait for the next scheduled Dependabot run, or you can manually trigger Dependabot on your repo by following [these instructions](https://docs.github.com/en/code-security/dependabot/working-with-dependabot/troubleshooting-dependabot-errors#triggering-a-dependabot-pull-request-manually) (specifically the bullet point that mentions “version updates” and the “Insights tab”).

---

<div class="post-metadata">

**Author:** ![kpobrien](https://avatars.discourse-cdn.com/v4/letter/k/c0e974/32.png) [@kpobrien](https://discourse.julialang.org/u/kpobrien)\
**Post date:** [April 3, 2024, 5:55pm UTC](https://discourse.julialang.org/t/ci-on-github/112471/9 "2024-04-03T17:55:31Z")

</div>

In the [CI.yml](https://github.com/ufechner7/KiteModels.jl/blob/main/.github/workflows/CI.yml) file in one of your repos, you are using both julia-actions/cache@v1 and actions/cache@v4. If you switch to only using actions/cache@v4, that will remove the Node.js 16 deprecation warnings.

This seems to be a reasonably common choice, for example in Symbolics and SciMLBase. actions/cache doesn’t appear to cache as much as julia-actions/cache, so it may be better in terms of energy/bandwidth to switch back to julia-actions/cache after it is updated or live with the deprecation warnings in the meantime.

I tried out the above [here](https://github.com/kpobrien/JosephsonCircuits.jl/blob/main/.github/workflows/CI.yml) and after setting `ignore-no-cache: true` for `julia-actions/julia-buildpkg@v1` there are no more CI warnings.
