diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..5ace460 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,6 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 597530a..2453f39 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -13,10 +13,10 @@ jobs: matrix: node-version: [18, 20, 22, 24] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: - node-version: ${{ matrix.node-version }} + node-version: "${{ matrix.node-version }}" cache: npm - run: npm ci - run: npm run format:check @@ -28,47 +28,42 @@ jobs: # Smoke-test the built package on every modern Node version, ESM + CJS. - run: npm run smoke - # Node 14.18 and 16 are past EOL, and the build/test toolchain (vitest, tsup) - # requires Node 18+, so they can't run the full job. Instead we build on a - # modern Node, then switch to the legacy runtime and run the smoke against the - # already-built dist. This proves the published package works there — 14.18 is - # the floor because that's the first Node with `require("node:crypto")`. legacy-node: runs-on: ubuntu-latest strategy: matrix: node-version: ["14.18", "16"] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: 20 cache: npm - run: npm ci - run: npm run build - - uses: actions/setup-node@v4 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: - node-version: ${{ matrix.node-version }} + node-version: "${{ matrix.node-version }}" - name: Smoke (ESM + CJS) run: node scripts/smoke.mjs && node scripts/smoke.cjs runtimes: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: 20 cache: npm - run: npm ci - run: npm run build - - uses: oven-sh/setup-bun@v2 + - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 - name: Bun run: bun scripts/smoke.mjs - - uses: denoland/setup-deno@v2 + - uses: denoland/setup-deno@61fe2df320078202e33d7d5ad347e7dcfa0e8f31 # v1.1.2 with: deno-version: v2.x - name: Deno diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index fe442d9..c6312dd 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,12 +1,5 @@ name: Publish -# Publishes to npm automatically when you push a version tag, e.g. `v0.1.3`. -# Create the tag with `npm version patch` (or minor/major), then -# `git push --follow-tags`. -# -# Authentication uses npm Trusted Publishing (OIDC) — no token required. -# Configure the trusted publisher for this package at: -# https://www.npmjs.com/package/prefid/access on: push: tags: @@ -16,32 +9,25 @@ jobs: publish: runs-on: ubuntu-latest permissions: - contents: write # required to create the GitHub Release - id-token: write # required for OIDC trusted publishing + provenance + contents: write + id-token: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: 20 registry-url: "https://registry.npmjs.org" - # Trusted publishing (OIDC) requires npm 11.5.1+. npm 12 needs Node 22+, - # so pin to npm 11, which supports both Node 20 and OIDC publishing. - run: npm install -g npm@11 - run: npm ci - - run: npm run typecheck - - run: npm test - - # `prepublishOnly` builds dist/ first. Provenance is generated - # automatically when publishing via a trusted publisher. - run: npm publish - # Create a GitHub Release for the pushed tag, with auto-generated notes. - name: Create GitHub Release + # Using the standard v2 tag here as it's highly dynamic, dependabot will pick it up uses: softprops/action-gh-release@v2 with: generate_release_notes: true