Skip to content

ci: bump actions/setup-java from 5.7.0 to 6.0.0 (+ fix red ScreenshotTests) - #2979

Merged
riccardobl merged 7 commits into
jMonkeyEngine:masterfrom
jaime-jmebot:jaime/supersede-pr-2972-fd6d8b4a
Sep 28, 2026
Merged

riccardobl merged 7 commits into
jMonkeyEngine:masterfrom
jaime-jmebot:jaime/supersede-pr-2972-fd6d8b4a

Conversation

@jaime-jmebot

@jaime-jmebot jaime-jmebot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Supersedes #2972

Requested by @riccardobl.

Supersedes #2972. Same dependency bump, plus the fix that makes CI green again.

The upgrade

All 10 actions/setup-java call sites go from v5.7.0 to v6.0.0 (.github/workflows/main.yml ×8, j3o-scan.yml, android-screenshot.yml). The one SHA-pinned reference is updated to dd06d9cba3e5552c54d9f8ea23572deb30010f7c, which is the commit tag v6.0.0 resolves to, so the # v6.0.0 comment stays accurate.

Nothing at our call sites is affected by the input renames in v6 — we only pass distribution and java-version, not jdkFile or any of the GPG settings.

Why CI was red

v6 added signature verification of the downloaded JDK, and it shells out to gpg to do it. The GitHub-hosted runners bundle gpg, so the other 10 jobs were unaffected. But ScreenshotTests runs inside ghcr.io/onemillionworlds/opengl-docker-image, which has no gpg binary, and setup-java treats that as a hard failure:

Verifying Java package signature...
##[error]Java setup process failed due to: Failed to verify signature for Temurin
version 25.0.4+101.0.LTS ...: Unable to locate executable file: gpg. Please verify
either the file path exists or the file can be found within a directory specified
by the PATH environment variable. Also check the file mode to verify the file is
executable.

Both the opengl and angle matrix legs died right at the "Setup the java environment" step, so no test actually ran — it was purely the version bump breaking these two jobs, not a real regression in the screenshot tests.

The fix

One added step in ScreenshotTests, before the Java setup:

- name: Install gpg
  run: |
    apt-get update -qq
    DEBIAN_FRONTEND=noninteractive apt-get install -y -qq gnupg

This is deliberately the same style as the "Start display server" step right below it, which already installs weston with apt-get and no sudo — the steps run as root in that container.

ScreenshotTests is the only containerized job in the repo (checked main.yml, j3o-scan.yml, android-screenshot.yml, format.yml, bounty.yml), so this is the only place that needs the extra package. Everything else runs on a GitHub-hosted runner that already has gpg.

I also considered turning verification off instead, but installing the missing binary keeps the security check working as upstream intended, which seemed like the better trade for a two-line change.

Testing

  • Confirmed against the actual failing job log: the error is Unable to locate executable file: gpg during Verifying Java package signature..., raised by setup-java immediately after the download.
  • Verified the container is Debian-based and runs as root by matching the existing apt-get usage in the same job.
  • Checked that gnupg provides the gpg binary the action looks up on PATH.
  • Confirmed no other job in the repo is containerized, so no further call sites need this.
  • No Java sources are touched by this PR; the only change is the workflow YAML.

dependabot Bot and others added 3 commits September 28, 2026 03:06
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.7.0 to 6.0.0.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@v5.7.0...v6)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Supersedes jMonkeyEngine#2972, which had the same bump but left CI red.

setup-java v6 verifies the JDK signature with gpg. The ScreenshotTests
container has no gpg, so both matrix legs failed. Install gnupg there.
@riccardobl

Copy link
Copy Markdown
Member

@jaime-jmebot complete the pr

@jaime-jmebot
jaime-jmebot marked this pull request as draft September 28, 2026 18:08
A file literally named `path`, containing the text .github/workflows/main.yml,
was committed by mistake. Nothing references it; delete it.
@riccardobl
riccardobl marked this pull request as ready for review September 28, 2026 19:04
@riccardobl
riccardobl merged commit e8cf975 into jMonkeyEngine:master Sep 28, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants