Repository navigation
chore(ci): pin third-party actions to commit SHAs in the 11 workflows that still floated @v7 - #1621
Merged
Merged
Conversation
…t SHAs in the 11 workflows that still floated @v7 Closes #1399. Seven of the eleven are the publish workflows that hold npm and PyPI credentials, so they are where a retagged upstream action matters most. Reuses the exact SHAs ci.yml and legacy-name-ratchet.yml already pin, so every workflow lands on one version per action: actions/checkout 3d3c42e5aac5ba805825da76410c181273ba90b1 v7.0.1 actions/setup-node 820762786026740c76f36085b0efc47a31fe5020 v7.0.0 actions/setup-python 5fda3b95a4ea91299a34e894583c3862153e4b97 v7.0.0 Dependabot's github-actions entry understands SHA pins, so updates keep flowing. Verified: grep -rn 'uses: [a-zA-Z].*@v[0-9]' .github/workflows/ prints nothing. Signed-off-by: erni <erni@caura.ai>
Contributor
|
Claude Code Review — skipped: PR author 'erni-a' is not a public member of the 'caura-ai' org |
This was referenced Sep 19, 2026
arkash20
approved these changes
Sep 20, 2026
Contributor
|
Claude Code Review — skipped: PR author 'erni-a' is not a public member of the 'caura-ai' org |
erni-a
added a commit
that referenced
this pull request
Sep 20, 2026
…client CI (#1622) ## Summary Closes #1403. The Python client CI runs ruff before pytest; the TypeScript client CI ran only `tsc` and `node --test`, so nothing caught formatting drift. This takes the smaller of the two routes the issue offers, **Prettier `--check`, not ESLint**: one dev dependency, one config key, and the source is about 300 lines, which does not justify a rule set to maintain. ESLint stays available as a later step if the client grows. - `clients/typescript/.prettierrc`: `printWidth: 110`, matching the `line-length = 110` the repo's ruff config already uses for Python, so both clients wrap at the same column. Everything else is Prettier's default. - `package.json`: `prettier ^3.6` as a devDependency (pinned through the lockfile, so CI and local runs agree), plus `lint` and `format` scripts so contributors run exactly what CI runs. - `client-typescript-ci.yml`: a `Lint (prettier)` step before `Build + test`, mirroring the Python workflow's ordering. - `src/`: the reformat the first run reports. No logic change. `npm install` and the Node-20-only matrix are left alone; #973 tracks them. Stacked on #1621 (same workflow file); merge that first and this rebases clean. ## Related Issue Closes #1403. ## Type of Change - [x] Other: CI gate for the TypeScript client ## How Has This Been Tested? - `npm run lint` fails on `main`'s source and passes after the reformat. - `npm test`: tsc clean, 31/31 pass on Node 20. - `.prettierrc` is not in the package `files` list, so the published tarball is unchanged. - The workflow is path-scoped to `clients/typescript/**`, so this PR triggers it and the new step is visible in the job log. ## Checklist - [x] I have read CONTRIBUTING.md - [x] Tests: existing suite covers the reformatted code; the lint step is the new gate - [x] Every commit is signed off (DCO) - [x] Not user-facing, no CHANGELOG entry Signed-off-by: erni <erni@caura.ai>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #1399.
Replaces the 23 floating
@v7references across 11 workflows with the full commit SHA plus version comment thatci.yml,codeql.yml,dco.yml,labels-sync.yml,legacy-name-ratchet.yml,publish-docker.ymlandsecurity-scan.ymlalready use. Same SHAs as those files, so every workflow is on one version per action:actions/checkout3d3c42e5aac5ba805825da76410c181273ba90b1actions/setup-node820762786026740c76f36085b0efc47a31fe5020actions/setup-python5fda3b95a4ea91299a34e894583c3862153e4b97Seven of the eleven are the
publish-*workflows that hold npm and PyPI credentials, which is where a retagged upstream tag matters most. Dependabot'sgithub-actionsentry understands SHA pins, so version updates keep arriving.Related Issue
Closes #1399. #1400 (
persist-credentials: false) landed first in #1481, so there is no textual conflict left.Type of Change
How Has This Been Tested?
grep -rn "uses: [a-zA-Z].*@v[0-9]" .github/workflows/prints nothing.actions/*pins: 24× checkout, 7× setup-node, 5× setup-python.Checklist