ci: bump actions/setup-java from 5.7.0 to 6.0.0 (+ fix red ScreenshotTests) - #2979
Merged
riccardobl merged 7 commits intoSep 28, 2026
Merged
riccardobl merged 7 commits into
riccardobl merged 7 commits into
Conversation
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.7.0 to 6.0.0. - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@v5.7.0...v6) --- updated-dependencies: - dependency-name: actions/setup-java dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Supersedes jMonkeyEngine#2972, which had the same bump but left CI red. setup-java v6 verifies the JDK signature with gpg. The ScreenshotTests container has no gpg, so both matrix legs failed. Install gnupg there.
Member
|
@jaime-jmebot complete the pr |
jaime-jmebot
marked this pull request as draft
September 28, 2026 18:08
A file literally named `path`, containing the text .github/workflows/main.yml, was committed by mistake. Nothing references it; delete it.
riccardobl
marked this pull request as ready for review
September 28, 2026 19:04
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supersedes #2972
Requested by @riccardobl.
Supersedes #2972. Same dependency bump, plus the fix that makes CI green again.
The upgrade
All 10
actions/setup-javacall sites go fromv5.7.0tov6.0.0(.github/workflows/main.yml×8,j3o-scan.yml,android-screenshot.yml). The one SHA-pinned reference is updated todd06d9cba3e5552c54d9f8ea23572deb30010f7c, which is the commit tagv6.0.0resolves to, so the# v6.0.0comment stays accurate.Nothing at our call sites is affected by the input renames in v6 — we only pass
distributionandjava-version, notjdkFileor any of the GPG settings.Why CI was red
v6 added signature verification of the downloaded JDK, and it shells out to
gpgto do it. The GitHub-hosted runners bundlegpg, so the other 10 jobs were unaffected. ButScreenshotTestsruns insideghcr.io/onemillionworlds/opengl-docker-image, which has nogpgbinary, and setup-java treats that as a hard failure:Both the
openglandanglematrix legs died right at the "Setup the java environment" step, so no test actually ran — it was purely the version bump breaking these two jobs, not a real regression in the screenshot tests.The fix
One added step in
ScreenshotTests, before the Java setup:This is deliberately the same style as the "Start display server" step right below it, which already installs
westonwithapt-getand nosudo— the steps run as root in that container.ScreenshotTestsis the only containerized job in the repo (checkedmain.yml,j3o-scan.yml,android-screenshot.yml,format.yml,bounty.yml), so this is the only place that needs the extra package. Everything else runs on a GitHub-hosted runner that already hasgpg.I also considered turning verification off instead, but installing the missing binary keeps the security check working as upstream intended, which seemed like the better trade for a two-line change.
Testing
Unable to locate executable file: gpgduringVerifying Java package signature..., raised by setup-java immediately after the download.apt-getusage in the same job.gnupgprovides thegpgbinary the action looks up onPATH.