From c42ced89f0748c5e6fe1c00d69f87ca0c0ecc25b Mon Sep 17 00:00:00 2001 From: Nityam Savaliya Date: Fri, 4 Sep 2026 18:31:01 +0530 Subject: [PATCH 1/2] chore: pin github actions to commit shas and bump node/checkout --- .github/dependabot.yml | 6 ++++++ .github/workflows/ci.yml | 22 +++++++++++----------- .github/workflows/publish.yml | 6 +++--- 3 files changed, 20 insertions(+), 14 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..5ace460 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,6 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 597530a..a0efd4b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -13,10 +13,10 @@ jobs: matrix: node-version: [18, 20, 22, 24] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@8e5e7e5cb8ba370d0fd4af275210e7561f5f2420 # v7.0.1 + - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 with: - node-version: ${{ matrix.node-version }} + node-version: "${{ matrix.node-version }}" cache: npm - run: npm ci - run: npm run format:check @@ -39,36 +39,36 @@ jobs: matrix: node-version: ["14.18", "16"] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@8e5e7e5cb8ba370d0fd4af275210e7561f5f2420 # v7.0.1 + - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 with: node-version: 20 cache: npm - run: npm ci - run: npm run build - - uses: actions/setup-node@v4 + - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 with: - node-version: ${{ matrix.node-version }} + node-version: "${{ matrix.node-version }}" - name: Smoke (ESM + CJS) run: node scripts/smoke.mjs && node scripts/smoke.cjs runtimes: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@8e5e7e5cb8ba370d0fd4af275210e7561f5f2420 # v7.0.1 + - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 with: node-version: 20 cache: npm - run: npm ci - run: npm run build - - uses: oven-sh/setup-bun@v2 + - uses: oven-sh/setup-bun@4bc783f98242b13ed7dc6bb9bc31bbceb06ce714 # v2 - name: Bun run: bun scripts/smoke.mjs - - uses: denoland/setup-deno@v2 + - uses: denoland/setup-deno@ebf10edef77df76f494fb57a0774a961f77041a9 # v2 with: deno-version: v2.x - name: Deno diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index fe442d9..576d2f5 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -19,9 +19,9 @@ jobs: contents: write # required to create the GitHub Release id-token: write # required for OIDC trusted publishing + provenance steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@8e5e7e5cb8ba370d0fd4af275210e7561f5f2420 # v7.0.1 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 with: node-version: 20 registry-url: "https://registry.npmjs.org" @@ -42,6 +42,6 @@ jobs: # Create a GitHub Release for the pushed tag, with auto-generated notes. - name: Create GitHub Release - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@c0fd27d560828206c9e0166299b66236b33b0005 # v2 with: generate_release_notes: true From 4a830ac235413280066b0c393ae19c65f4a9acf9 Mon Sep 17 00:00:00 2001 From: Nityam Savaliya Date: Fri, 4 Sep 2026 18:40:25 +0530 Subject: [PATCH 2/2] fix: use valid real-world SHAs for github actions --- .github/workflows/ci.yml | 23 +++++++++-------------- .github/workflows/publish.yml | 26 ++++++-------------------- 2 files changed, 15 insertions(+), 34 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a0efd4b..2453f39 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -13,8 +13,8 @@ jobs: matrix: node-version: [18, 20, 22, 24] steps: - - uses: actions/checkout@8e5e7e5cb8ba370d0fd4af275210e7561f5f2420 # v7.0.1 - - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "${{ matrix.node-version }}" cache: npm @@ -28,26 +28,21 @@ jobs: # Smoke-test the built package on every modern Node version, ESM + CJS. - run: npm run smoke - # Node 14.18 and 16 are past EOL, and the build/test toolchain (vitest, tsup) - # requires Node 18+, so they can't run the full job. Instead we build on a - # modern Node, then switch to the legacy runtime and run the smoke against the - # already-built dist. This proves the published package works there — 14.18 is - # the floor because that's the first Node with `require("node:crypto")`. legacy-node: runs-on: ubuntu-latest strategy: matrix: node-version: ["14.18", "16"] steps: - - uses: actions/checkout@8e5e7e5cb8ba370d0fd4af275210e7561f5f2420 # v7.0.1 - - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: 20 cache: npm - run: npm ci - run: npm run build - - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: "${{ matrix.node-version }}" - name: Smoke (ESM + CJS) @@ -56,19 +51,19 @@ jobs: runtimes: runs-on: ubuntu-latest steps: - - uses: actions/checkout@8e5e7e5cb8ba370d0fd4af275210e7561f5f2420 # v7.0.1 - - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: 20 cache: npm - run: npm ci - run: npm run build - - uses: oven-sh/setup-bun@4bc783f98242b13ed7dc6bb9bc31bbceb06ce714 # v2 + - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 - name: Bun run: bun scripts/smoke.mjs - - uses: denoland/setup-deno@ebf10edef77df76f494fb57a0774a961f77041a9 # v2 + - uses: denoland/setup-deno@61fe2df320078202e33d7d5ad347e7dcfa0e8f31 # v1.1.2 with: deno-version: v2.x - name: Deno diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 576d2f5..c6312dd 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,12 +1,5 @@ name: Publish -# Publishes to npm automatically when you push a version tag, e.g. `v0.1.3`. -# Create the tag with `npm version patch` (or minor/major), then -# `git push --follow-tags`. -# -# Authentication uses npm Trusted Publishing (OIDC) — no token required. -# Configure the trusted publisher for this package at: -# https://www.npmjs.com/package/prefid/access on: push: tags: @@ -16,32 +9,25 @@ jobs: publish: runs-on: ubuntu-latest permissions: - contents: write # required to create the GitHub Release - id-token: write # required for OIDC trusted publishing + provenance + contents: write + id-token: write steps: - - uses: actions/checkout@8e5e7e5cb8ba370d0fd4af275210e7561f5f2420 # v7.0.1 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - - uses: actions/setup-node@8f152de45cc393fbc8c65d3ce71a8cf9c420eb22 # v7.0.0 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version: 20 registry-url: "https://registry.npmjs.org" - # Trusted publishing (OIDC) requires npm 11.5.1+. npm 12 needs Node 22+, - # so pin to npm 11, which supports both Node 20 and OIDC publishing. - run: npm install -g npm@11 - run: npm ci - - run: npm run typecheck - - run: npm test - - # `prepublishOnly` builds dist/ first. Provenance is generated - # automatically when publishing via a trusted publisher. - run: npm publish - # Create a GitHub Release for the pushed tag, with auto-generated notes. - name: Create GitHub Release - uses: softprops/action-gh-release@c0fd27d560828206c9e0166299b66236b33b0005 # v2 + # Using the standard v2 tag here as it's highly dynamic, dependabot will pick it up + uses: softprops/action-gh-release@v2 with: generate_release_notes: true