GitHub Actions dropped Node 20: calling Sume needs no Node
Node 20 is gone from GitHub Actions runners. Sume's CLI is a native binary and the API is plain HTTPS, so a workflow step can call it with no Node version.

Calling Sume from a workflow does not depend on a Node version. The Sume CLI is a native binary installed with one curl line, and the API is HTTPS, so a run: step with curl works on a runner that only has Node 24. Only JavaScript actions you use are affected by the Node 20 removal, and you update those to their latest releases.
GitHub's side is from its 2026-09-23 changelog (read 2026-09-30). Sume's side is from the CLI install and Jobs and results docs.
What did GitHub change?
The changelog says Node 20 is no longer available on Actions runners, runners now use Node 24 for JavaScript actions, and the temporary ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION opt-out is gone. Maintainers should set runs.using to node24; users should move to the latest versions of actions that support Node 24.
Which Sume paths touch Node at all?
| Path | Runtime needed | Source |
|---|---|---|
curl to https://api.sume.com/v1 | None beyond curl | Jobs and results |
Native CLI via curl https://cli.sume.com/install -fsS | bash | None; it is a native binary | Install and update |
@sume-com/sdk | Node 18+, Bun, Deno or Workers | TypeScript SDK |
What does a step look like?
Store the API key as a repository secret and expose it as SUME_API_KEY in the step's environment. Derive the Idempotency-Key from something stable such as the commit, so a re-run of the job returns the original job instead of billing a second one. The submit is async, which returns a job id at once.
set -euo pipefail
curl -fsS -X POST https://api.sume.com/v1/image-1.0/generate \
-H "Authorization: Bearer $SUME_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: release-image-$GITHUB_SHA" \
-d '{"prompt":"Product hero shot of a matte black bottle on marble","mode":"async"}'What about the CLI in CI?
The docs say manual API-key setup and environment variables are still supported for CI and server automation, so after the installer runs, set SUME_API_KEY and call sume. The installer verifies the download against checksums.txt. For a pinned install, the docs say to replace latest in the release URL with a tag.
What if the step is cancelled or times out?
Do not resubmit the paid request because a local process timed out. Reuse the same Idempotency-Key for a retry, and read the job with GET /v1/jobs/{id}/status. Re-running a workflow with the same key covers the details.
Sources
Related posts
More in Developers
- Google Cloud Tasks retry per task: pair it with a Sume key
Cloud Tasks now sets retry parameters per task (GA 30 Sep 2026). When a task calls a Sume submit, send the same Idempotency-Key on every attempt.
- Google Cloud Workflows callback needs an IAM token: relay Sume
A Cloud Workflows callback URL needs the workflows.callbacks.send permission and a Bearer token. Sume webhooks cannot carry one, so relay after verifying.
- google/veo-3.1 style ids vs Sume: bare video model ids
OpenRouter names video models org/slug, such as google/veo-3.1. Sume uses bare catalog ids like seedance-2 and never a provider prefix. How to port an id.
- gpt-4o-transcribe-diarize retiring: Sume STT has no speaker labels
OpenAI lists gpt-4o-transcribe-diarize for removal on Feb 26, 2027. Sume STT returns words and sentences with timings, but no speaker field.
Written by Sume