From 84f2c416def5974bc2d78e89ede9561b8bf04be8 Mon Sep 17 00:00:00 2001 From: Augustin Mauroy <97875033+AugustinMauroy@users.noreply.github.com> Date: Mon, 13 Jul 2026 23:49:00 +0200 Subject: [PATCH] setup(ci): update + clean --- .github/workflows/code-quality.yml | 52 ++++++++------------------ .github/workflows/codemod_publish.yml | 11 +++++- .github/workflows/dir-organisation.yml | 13 +++---- .github/workflows/lint-workflows.yml | 12 +++--- .github/workflows/pr.yml | 12 +++--- .github/workflows/workflow-tests.yml | 12 +++--- .nvmrc | 2 +- 7 files changed, 48 insertions(+), 66 deletions(-) diff --git a/.github/workflows/code-quality.yml b/.github/workflows/code-quality.yml index 55552273..4f0867df 100644 --- a/.github/workflows/code-quality.yml +++ b/.github/workflows/code-quality.yml @@ -6,7 +6,7 @@ name: Code Quality on: push: - branches: ["*"] + branches: ["main"] paths: - "recipes/**/*.js" - "recipes/**/*.ts" @@ -15,7 +15,7 @@ on: - "utils/**/*.ts" - "utils/package.json" - "package.json" - - ".github/workflows/ci.yml" + - ".github/workflows/code-quality.yml" pull_request: branches: ["*"] paths: @@ -26,7 +26,7 @@ on: - "utils/**/*.ts" - "utils/**/package.json" - "package.json" - - ".github/workflows/ci.yml" + - ".github/workflows/code-quality.yml" types: - opened - ready_for_review @@ -37,39 +37,16 @@ permissions: contents: read jobs: - get-matrix: - name: Get Node + OS matrix - runs-on: ubuntu-latest - - if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} - - outputs: - latest: ${{ steps.set-matrix.outputs.requireds }} - steps: - - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 - with: - egress-policy: audit - - - uses: ljharb/actions/node/matrix@7f214d8efdbdcefc96ad9689663ef387a195deec # main - id: set-matrix - with: - versionsAsRoot: true - type: majors - preset: ">= 22" # glob is not backported below 22.x - lint-and-types: name: Lint & types runs-on: ubuntu-slim - if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} steps: - # FIXME https://github.com/step-security/harden-runner/issues/627 - # - name: Harden the runner (Audit all outbound calls) - # uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 - # with: - # egress-policy: audit + - name: Harden the runner (Audit all outbound calls) + uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 + with: + egress-policy: audit - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: @@ -83,7 +60,6 @@ jobs: test: name: Before/After tests runs-on: ${{ matrix.os }} - if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} strategy: @@ -91,12 +67,12 @@ jobs: matrix: os: - macos-latest - - ubuntu-latest + - ubuntu-slim - windows-latest steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 + uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit @@ -106,7 +82,9 @@ jobs: persist-credentials: false show-progress: false + # ubuntu-slim already include lts node so we don't need to setup node on ubuntu-slim runner - name: Set up Node.js + if: ${{ matrix.os != 'ubuntu-slim' }} uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: cache: "npm" @@ -118,7 +96,7 @@ jobs: - name: Run tests related to changes shell: bash run: > - changed_paths=$(git diff --name-only ${{ github.event.pull_request.base.sha }} ${{ github.sha }}) + changed_paths=$(git diff --name-only ${{ github.event.pull_request.base.sha || github.event.before }} ${{ github.sha }}) # run everything? if echo "$changed_paths" | grep -qE '^(package\.json|\.github/workflows/ci\.yml|utils/)$'; then @@ -129,8 +107,8 @@ jobs: # run for specific workspace(s) npm run test $( echo "$changed_paths" \ - | grep '^recipes/' - | cut -d/ -f1,2 - | sort -u + | grep '^recipes/' \ + | cut -d/ -f1,2 \ + | sort -u \ | sed 's/^/--workspace=/' ) diff --git a/.github/workflows/codemod_publish.yml b/.github/workflows/codemod_publish.yml index f6ec21e3..6f64d486 100644 --- a/.github/workflows/codemod_publish.yml +++ b/.github/workflows/codemod_publish.yml @@ -32,9 +32,16 @@ jobs: steps: - name: Harden Runner - uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 + uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0 with: - egress-policy: audit + egress-policy: block + allowed-endpoints: > + api.github.com:443 + app.codemod.com:443 + github.com:443 + registry.npmjs.org:443 + release-assets.githubusercontent.com:443 + us.i.posthog.com:443 - name: Checkout repository uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 diff --git a/.github/workflows/dir-organisation.yml b/.github/workflows/dir-organisation.yml index 251addf4..00cb557c 100644 --- a/.github/workflows/dir-organisation.yml +++ b/.github/workflows/dir-organisation.yml @@ -1,5 +1,7 @@ # yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json +# For more information see: https://docs.github.com/en/actions/writing-workflows/choosing-what-your-workflow-does/running-variations-of-jobs-in-a-workflow + name: Code Quality on: @@ -18,20 +20,17 @@ permissions: pull-requests: read jobs: - forbid-junkdrawer-tests: name: Test organisation - runs-on: ubuntu-slim if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} steps: - # FIXME https://github.com/step-security/harden-runner/issues/627 - # - name: Harden the runner (Audit all outbound calls) - # uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0 - # with: - # egress-policy: audit + - name: Harden the runner (Audit all outbound calls) + uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 + with: + egress-policy: audit - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: diff --git a/.github/workflows/lint-workflows.yml b/.github/workflows/lint-workflows.yml index e71990b1..0714ab90 100644 --- a/.github/workflows/lint-workflows.yml +++ b/.github/workflows/lint-workflows.yml @@ -6,7 +6,7 @@ name: Workflow Quality on: push: - branches: ["*"] + branches: ["main"] paths: - ".github/workflows/*.yml" - "recipes/*/*.yml" @@ -25,20 +25,22 @@ permissions: contents: read jobs: - validate-yaml: name: Validate YAML files + runs-on: ubuntu-slim if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} - runs-on: ubuntu-latest - steps: - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 + uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + + - name: Install yamllint + run: pip install yamllint + - name: Validate YAML files run: yamllint -c .yamllint.yaml -f github ./ diff --git a/.github/workflows/pr.yml b/.github/workflows/pr.yml index 12d6e366..2b87bfa2 100644 --- a/.github/workflows/pr.yml +++ b/.github/workflows/pr.yml @@ -4,8 +4,7 @@ name: PR Quality on: pull_request: - branches: - - main + branches: ["main"] types: - edited - opened @@ -23,11 +22,10 @@ jobs: if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} steps: - # FIXME https://github.com/step-security/harden-runner/issues/627 - # - name: Harden Runner - # uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0 - # with: - # egress-policy: audit + - name: Harden the runner (Audit all outbound calls) + uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 + with: + egress-policy: audit - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 diff --git a/.github/workflows/workflow-tests.yml b/.github/workflows/workflow-tests.yml index 859077af..c0431167 100644 --- a/.github/workflows/workflow-tests.yml +++ b/.github/workflows/workflow-tests.yml @@ -6,7 +6,7 @@ name: Workflow Quality on: push: - branches: ["*"] + branches: ["main"] paths: - ".github/workflows/*.yml" - ".github/scripts/*" @@ -25,7 +25,6 @@ permissions: contents: read jobs: - run-workflow-script-tests: name: Test scripts runs-on: ubuntu-slim @@ -33,11 +32,10 @@ jobs: if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} steps: - # FIXME https://github.com/step-security/harden-runner/issues/627 - # - name: Harden the runner (Audit all outbound calls) - # uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0 - # with: - # egress-policy: audit + - name: Harden the runner (Audit all outbound calls) + uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 + with: + egress-policy: audit - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: diff --git a/.nvmrc b/.nvmrc index a45fd52c..b009dfb9 100644 --- a/.nvmrc +++ b/.nvmrc @@ -1 +1 @@ -24 +lts/*