Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 15 additions & 37 deletions .github/workflows/code-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ name: Code Quality

on:
push:
branches: ["*"]
branches: ["main"]
paths:
- "recipes/**/*.js"
- "recipes/**/*.ts"
Expand All @@ -15,7 +15,7 @@ on:
- "utils/**/*.ts"
- "utils/package.json"
- "package.json"
- ".github/workflows/ci.yml"
- ".github/workflows/code-quality.yml"
pull_request:
branches: ["*"]
paths:
Expand All @@ -26,7 +26,7 @@ on:
- "utils/**/*.ts"
- "utils/**/package.json"
- "package.json"
- ".github/workflows/ci.yml"
- ".github/workflows/code-quality.yml"
types:
- opened
- ready_for_review
Expand All @@ -37,39 +37,16 @@ permissions:
contents: read

jobs:
get-matrix:
name: Get Node + OS matrix
runs-on: ubuntu-latest

if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}

outputs:
latest: ${{ steps.set-matrix.outputs.requireds }}
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
with:
egress-policy: audit

- uses: ljharb/actions/node/matrix@7f214d8efdbdcefc96ad9689663ef387a195deec # main
id: set-matrix
with:
versionsAsRoot: true
type: majors
preset: ">= 22" # glob is not backported below 22.x

lint-and-types:
name: Lint & types
runs-on: ubuntu-slim

if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}

steps:
# FIXME https://github.com/step-security/harden-runner/issues/627
# - name: Harden the runner (Audit all outbound calls)
# uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
# with:
# egress-policy: audit
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
Expand All @@ -83,20 +60,19 @@ jobs:
test:
name: Before/After tests
runs-on: ${{ matrix.os }}

if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}

strategy:
fail-fast: false
matrix:
os:
- macos-latest
- ubuntu-latest
- ubuntu-slim
- windows-latest

steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

Expand All @@ -106,7 +82,9 @@ jobs:
persist-credentials: false
show-progress: false

# ubuntu-slim already include lts node so we don't need to setup node on ubuntu-slim runner
- name: Set up Node.js
if: ${{ matrix.os != 'ubuntu-slim' }}
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
cache: "npm"
Expand All @@ -118,7 +96,7 @@ jobs:
- name: Run tests related to changes
shell: bash
run: >
changed_paths=$(git diff --name-only ${{ github.event.pull_request.base.sha }} ${{ github.sha }})
changed_paths=$(git diff --name-only ${{ github.event.pull_request.base.sha || github.event.before }} ${{ github.sha }})

# run everything?
if echo "$changed_paths" | grep -qE '^(package\.json|\.github/workflows/ci\.yml|utils/)$'; then
Expand All @@ -129,8 +107,8 @@ jobs:
# run for specific workspace(s)
npm run test $(
echo "$changed_paths" \
| grep '^recipes/'
| cut -d/ -f1,2
| sort -u
| grep '^recipes/' \
| cut -d/ -f1,2 \
| sort -u \
| sed 's/^/--workspace=/'
)
11 changes: 9 additions & 2 deletions .github/workflows/codemod_publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,9 +32,16 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
Comment thread
AugustinMauroy marked this conversation as resolved.
with:
egress-policy: audit
egress-policy: block
allowed-endpoints: >
api.github.com:443
app.codemod.com:443
github.com:443
registry.npmjs.org:443
release-assets.githubusercontent.com:443
us.i.posthog.com:443

- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
Expand Down
13 changes: 6 additions & 7 deletions .github/workflows/dir-organisation.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json

# For more information see: https://docs.github.com/en/actions/writing-workflows/choosing-what-your-workflow-does/running-variations-of-jobs-in-a-workflow

name: Code Quality

on:
Expand All @@ -18,20 +20,17 @@ permissions:
pull-requests: read

jobs:

forbid-junkdrawer-tests:
name: Test organisation

runs-on: ubuntu-slim

if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}

steps:
# FIXME https://github.com/step-security/harden-runner/issues/627
# - name: Harden the runner (Audit all outbound calls)
# uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
# with:
# egress-policy: audit
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
Expand Down
12 changes: 7 additions & 5 deletions .github/workflows/lint-workflows.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ name: Workflow Quality

on:
push:
branches: ["*"]
branches: ["main"]
paths:
- ".github/workflows/*.yml"
- "recipes/*/*.yml"
Expand All @@ -25,20 +25,22 @@ permissions:
contents: read

jobs:

validate-yaml:
name: Validate YAML files
runs-on: ubuntu-slim

if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}

runs-on: ubuntu-latest

steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Install yamllint
run: pip install yamllint

- name: Validate YAML files
run: yamllint -c .yamllint.yaml -f github ./
12 changes: 5 additions & 7 deletions .github/workflows/pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@ name: PR Quality

on:
pull_request:
branches:
- main
branches: ["main"]
types:
- edited
- opened
Expand All @@ -23,11 +22,10 @@ jobs:
if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}

steps:
# FIXME https://github.com/step-security/harden-runner/issues/627
# - name: Harden Runner
# uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
# with:
# egress-policy: audit
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
Expand Down
12 changes: 5 additions & 7 deletions .github/workflows/workflow-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ name: Workflow Quality

on:
push:
branches: ["*"]
branches: ["main"]
paths:
- ".github/workflows/*.yml"
- ".github/scripts/*"
Expand All @@ -25,19 +25,17 @@ permissions:
contents: read

jobs:

run-workflow-script-tests:
name: Test scripts
runs-on: ubuntu-slim

if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}

steps:
# FIXME https://github.com/step-security/harden-runner/issues/627
# - name: Harden the runner (Audit all outbound calls)
# uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
# with:
# egress-policy: audit
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
Expand Down
2 changes: 1 addition & 1 deletion .nvmrc
Original file line number Diff line number Diff line change
@@ -1 +1 @@
24
lts/*
Loading