From f0c62c218b960c59a54a3433e36ef02cb7cc8a26 Mon Sep 17 00:00:00 2001 From: shendeguize <30931540+shendeguize@users.noreply.github.com> Date: Wed, 16 Sep 2026 13:20:50 +0800 Subject: [PATCH] fix(pages): pin artifact upload directly Avoid the transitive version tag rejected by repository policy, enforce the direct artifact contract in tests, and advance child pins. --- .github/workflows/preview-pages.yml | 13 ++++++++++--- AdvisedOrganons | 2 +- OrganonCore | 2 +- tests/release-site-data.test.mjs | 10 +++++++--- 4 files changed, 19 insertions(+), 8 deletions(-) diff --git a/.github/workflows/preview-pages.yml b/.github/workflows/preview-pages.yml index f152b7e..ada35ee 100644 --- a/.github/workflows/preview-pages.yml +++ b/.github/workflows/preview-pages.yml @@ -31,9 +31,14 @@ jobs: env: ORGANON_CORE_ROOT: ${{ github.workspace }}/product/OrganonCore run: npm run check:site - - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa + - name: Archive Pages artifact + run: tar --dereference --directory product/dist/site/ -cvf "$RUNNER_TEMP/artifact.tar" --exclude=.git --exclude=.github . + - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 with: - path: product/dist/site/ + name: github-pages-${{ github.run_attempt }} + path: ${{ runner.temp }}/artifact.tar + retention-days: 1 + if-no-files-found: error deploy: needs: build runs-on: ubuntu-24.04 @@ -46,4 +51,6 @@ jobs: url: ${{ steps.deployment.outputs.page_url }} steps: - uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e - id: deployment \ No newline at end of file + id: deployment + with: + artifact_name: github-pages-${{ github.run_attempt }} \ No newline at end of file diff --git a/AdvisedOrganons b/AdvisedOrganons index bfa4992..a1ba2fc 160000 --- a/AdvisedOrganons +++ b/AdvisedOrganons @@ -1 +1 @@ -Subproject commit bfa4992f492d431aec3d056cc98ab378b22033f9 +Subproject commit a1ba2fc9effbcb6f49dae1aceb36765f552dc3f8 diff --git a/OrganonCore b/OrganonCore index 28f5a01..d653744 160000 --- a/OrganonCore +++ b/OrganonCore @@ -1 +1 @@ -Subproject commit 28f5a01274489ae6795e6b76b34c74426b16d550 +Subproject commit d6537446ed3a365dc1a4c34ce64f3be691761b3b diff --git a/tests/release-site-data.test.mjs b/tests/release-site-data.test.mjs index 4c55fb4..cc91277 100644 --- a/tests/release-site-data.test.mjs +++ b/tests/release-site-data.test.mjs @@ -105,12 +105,16 @@ test('preview Pages deploy current main without creating verified release state' assert.match(workflow, /deploy:[\s\S]*?permissions:\n pages: write\n id-token: write/); const actions = [...workflow.matchAll(/uses: ([^\s]+)/g)].map(match => match[1]); assert(actions.every(action => /@[a-f0-9]{40}$/.test(action))); - assert(actions.includes('actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa')); + assert(actions.includes('actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02')); + assert(!actions.some(action => action.startsWith('actions/upload-pages-artifact@'))); assert(actions.includes('actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e')); assert.match(workflow, /actions\/checkout@[a-f0-9]{40}[\s\S]*?persist-credentials: false/); assert.match(workflow, /deploy:\n needs: build/); - assert.match(workflow, new RegExp(`path: ${output.replaceAll('/', '\\/')}`)); - assert(workflow.indexOf('run: npm run check:site') < workflow.indexOf('actions/upload-pages-artifact@')); + assert.match(workflow, new RegExp(`--directory ${output.replaceAll('/', '\\/')}`)); + assert.match(workflow, /name: github-pages-\$\{\{ github\.run_attempt \}\}[\s\S]*?path: \$\{\{ runner\.temp \}\}\/artifact\.tar/); + assert.match(workflow, /deploy-pages@[a-f0-9]{40}[\s\S]*?artifact_name: github-pages-\$\{\{ github\.run_attempt \}\}/); + assert(workflow.indexOf('run: npm run check:site') < workflow.indexOf('name: Archive Pages artifact')); + assert(workflow.indexOf('name: Archive Pages artifact') < workflow.indexOf('actions/upload-artifact@')); assert.doesNotMatch(workflow, /contents: write|site-data\.mjs|GOVERNANCE_AUDIT_TOKEN|release-manifest/); } const builder = fs.readFileSync(path.join(workspace, 'OrganonCore/tools/site/build.mjs'), 'utf8');