Skip to content

Chore: Actions updates and cleanup - #8377

Merged
AustinMroz merged 14 commits into
mainfrom
drjkl/ci-actions-update
Jan 29, 2026
Merged

Chore: Actions updates and cleanup#8377
AustinMroz merged 14 commits into
mainfrom
drjkl/ci-actions-update

Conversation

@DrJKL

@DrJKL DrJKL commented Jan 28, 2026

Copy link
Copy Markdown
Contributor

Summary

...

┆Issue is synchronized with this Notion page by Unito

DrJKL and others added 4 commits January 28, 2026 01:33
- actions/checkout v5 -> v6

- actions/setup-node v4/v5 -> v6

- actions/setup-python v4/v5 -> v6

- actions/upload-artifact v4 -> v6

- actions/download-artifact v4 -> v7

- actions/cache v4 -> v5

- actions/github-script v7 -> v8

- peter-evans/create-pull-request SHA/v7 -> v8

- peter-evans/find-comment SHA -> v4

- peter-evans/create-or-update-comment SHA -> v5

- chromaui/action latest -> v13

- dawidd6/action-download-artifact v11 -> v12

- shimataro/ssh-key-action SHA -> v2

- softprops/action-gh-release SHA -> v2

- pypa/gh-action-pypi-publish SHA -> v1

- anthropics/claude-code-action v1.0.6 -> v1

- Standardized pnpm/action-setup to v4

Amp-Thread-ID: https://ampcode.com/threads/T-019c03e2-7e02-7209-8931-ec36a0fa6ea7
Co-authored-by: Amp <amp@ampcode.com>
- Fix setup-frontend action to save cache (not just restore)

- Standardize 6 workflows to use setup-frontend composite action

- Remove unnecessary checkout from draft_release job

- Remove checkout from merge-reports job (only needs pnpm dlx)

- Reduce fetch-depth in weekly-docs-check (0 -> 50)

Amp-Thread-ID: https://ampcode.com/threads/T-019c03f5-8ea2-7192-b2f1-f89a78402bec
Co-authored-by: Amp <amp@ampcode.com>
@coderabbitai

coderabbitai Bot commented Jan 28, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Bumps and pins GitHub Action versions across many workflows, consolidates frontend setup into a local setup action, adds Pinact configuration for validating/pinning action SHAs, adds a YAML lint rule for comment spacing, and ensures LF endings for .yml files. No functional application logic changed.

Changes

Cohort / File(s) Summary
Repo attributes & linters
/.gitattributes, /.yamllint
Add *.yml text eol=lf and a new YAML lint rule enforcing one space before comments.
Pinact config
/.pinact.yaml
Add Pinact v3 configuration to validate/pin GitHub Action SHAs and an ignore list for certain official actions.
Local actions
.github/actions/...
/.github/actions/comment-release-links/action.yaml, /.github/actions/setup-comfyui-server/action.yaml, /.github/actions/setup-frontend/action.yaml, /.github/actions/setup-playwright/action.yaml
Update action version references (checkout, setup-python, setup-node, pnpm-action pin, cache upgrade); remove the tool-cache restore step from setup-frontend; add inline version comments in some actions.
Workflows — general checkout & tooling bumps
.github/workflows/...
api-update-*.yaml, ci-*.yaml, ci-tests-*.yaml, ci-lint-format.yaml, ci-size-data.yaml, ci-yaml-validation.yaml, ci-python-validation.yaml, ci-json-validation.yaml, ci-tests-*, ci-tests-e2e*.yaml
Widespread upgrade of actions/checkout@v5→@v6 and other core actions (setup-node/python, pnpm action pinned to commit); consolidate pnpm/node/install steps into a single Setup frontend local action in many jobs; upgrade artifact/cache/github-script versions.
Workflows — release & publish
.github/workflows/...
release-*.yaml, publish-desktop-ui*.yaml, pr-*, weekly-docs-check.yaml, cloud-backport-tag.yaml, release-draft-create.yaml, release-pypi-dev.yaml
Upgrade action versions (checkout, setup-node, pnpm pin, upload/download-artifact, GH release and PyPI publish actions), add/pin specific commits, adjust some checkout flags (e.g., fetch-depth or persist-credentials), and add a job to validate action pins.
New workflow
.github/workflows/ci-validate-action-pins.yaml
Add a workflow to run suzuki-shunsuke/pinact-action (pinned) to validate action SHA pins on changes to workflows/actions.

Possibly related PRs

Suggested reviewers

  • AustinMroz
  • christian-byrne
  • benceruleanlu

Comment @coderabbitai help to get the list of available commands and usage tips.

@DrJKL
DrJKL requested a review from snomiao January 28, 2026 20:33
@github-actions

github-actions Bot commented Jan 28, 2026

Copy link
Copy Markdown

🎨 Storybook Build Status

Build completed successfully!

⏰ Completed at: 01/29/2026, 04:59:33 AM UTC

🔗 Links


🎉 Your Storybook is ready for review!

@github-actions

github-actions Bot commented Jan 28, 2026

Copy link
Copy Markdown

🎭 Playwright Tests: ✅ Passed

Results: 507 passed, 0 failed, 0 flaky, 8 skipped (Total: 515)

📊 Browser Reports
  • chromium: View Report (✅ 495 / ❌ 0 / ⚠️ 0 / ⏭️ 8)
  • chromium-2x: View Report (✅ 2 / ❌ 0 / ⚠️ 0 / ⏭️ 0)
  • chromium-0.5x: View Report (✅ 1 / ❌ 0 / ⚠️ 0 / ⏭️ 0)
  • mobile-chrome: View Report (✅ 9 / ❌ 0 / ⚠️ 0 / ⏭️ 0)

@socket-security

socket-security Bot commented Jan 28, 2026

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@github-actions

github-actions Bot commented Jan 28, 2026

Copy link
Copy Markdown

Bundle Size Report

Summary

  • Raw size: 22.1 MB baseline 22.1 MB — 🟢 -205 B
  • Gzip: 4.6 MB baseline 4.6 MB — 🟢 -122 B
  • Brotli: 3.41 MB baseline 3.41 MB — 🔴 +84 B
  • Bundles: 173 current • 173 baseline • 81 added / 81 removed

Category Glance
Other 🟢 -198 B (7.05 MB) · Panels & Settings 🟢 -8 B (471 kB) · Data & Services 🔴 +1 B (2.7 MB) · Vendor & Third-Party ⚪ 0 B (10.7 MB) · Graph Workspace ⚪ 0 B (973 kB) · Views & Navigation ⚪ 0 B (80.7 kB) · + 5 more

Per-category breakdown
App Entry Points — 26 kB (baseline 26 kB) • ⚪ 0 B

Main entry bundles and manifests

File Before After Δ Raw Δ Gzip Δ Brotli
assets/index-BIjc-ZCy.js (removed) 26 kB 🟢 -26 kB 🟢 -7.51 kB 🟢 -6.62 kB
assets/index-hKGksho7.js (new) 26 kB 🔴 +26 kB 🔴 +7.5 kB 🔴 +6.61 kB

Status: 1 added / 1 removed

Graph Workspace — 973 kB (baseline 973 kB) • ⚪ 0 B

Graph editor runtime, canvas, workflow orchestration

File Before After Δ Raw Δ Gzip Δ Brotli
assets/GraphView-B4q21E-G.js (new) 973 kB 🔴 +973 kB 🔴 +197 kB 🔴 +148 kB
assets/GraphView-Dj25xXsF.js (removed) 973 kB 🟢 -973 kB 🟢 -197 kB 🟢 -148 kB

Status: 1 added / 1 removed

Views & Navigation — 80.7 kB (baseline 80.7 kB) • ⚪ 0 B

Top-level views, pages, and routed surfaces

File Before After Δ Raw Δ Gzip Δ Brotli
assets/CloudSurveyView-yOL0ioEy.js (new) 17.1 kB 🔴 +17.1 kB 🔴 +3.6 kB 🔴 +3.05 kB
assets/CloudSurveyView-ZIBwPnuJ.js (removed) 17.1 kB 🟢 -17.1 kB 🟢 -3.61 kB 🟢 -3.05 kB
assets/CloudLoginView-BJT5KUda.js (new) 11.8 kB 🔴 +11.8 kB 🔴 +3.09 kB 🔴 +2.72 kB
assets/CloudLoginView-C_4tyFfy.js (removed) 11.8 kB 🟢 -11.8 kB 🟢 -3.09 kB 🟢 -2.71 kB
assets/UserCheckView-BUimCvGO.js (new) 10.5 kB 🔴 +10.5 kB 🔴 +2.45 kB 🔴 +2.13 kB
assets/UserCheckView-ic1GHEvq.js (removed) 10.5 kB 🟢 -10.5 kB 🟢 -2.45 kB 🟢 -2.13 kB
assets/CloudLayoutView-BTL5W7lr.js (removed) 8.54 kB 🟢 -8.54 kB 🟢 -2.24 kB 🟢 -1.96 kB
assets/CloudLayoutView-DDGQitgr.js (new) 8.54 kB 🔴 +8.54 kB 🔴 +2.24 kB 🔴 +1.95 kB
assets/CloudSignupView-Crv9Xi1T.js (removed) 8.18 kB 🟢 -8.18 kB 🟢 -2.33 kB 🟢 -2.02 kB
assets/CloudSignupView-pjgYl4El.js (new) 8.18 kB 🔴 +8.18 kB 🔴 +2.33 kB 🔴 +2.02 kB
assets/CloudForgotPasswordView-BLo3mCoo.js (new) 6.26 kB 🔴 +6.26 kB 🔴 +1.92 kB 🔴 +1.69 kB
assets/CloudForgotPasswordView-BpCbC8b6.js (removed) 6.26 kB 🟢 -6.26 kB 🟢 -1.93 kB 🟢 -1.69 kB
assets/UserSelectView-ftBqdrOB.js (new) 5.28 kB 🔴 +5.28 kB 🔴 +1.76 kB 🔴 +1.57 kB
assets/UserSelectView-ip1gjj8Q.js (removed) 5.28 kB 🟢 -5.28 kB 🟢 -1.76 kB 🟢 -1.57 kB
assets/CloudSubscriptionRedirectView-BOWcngNj.js (new) 5.27 kB 🔴 +5.27 kB 🔴 +1.73 kB 🔴 +1.54 kB
assets/CloudSubscriptionRedirectView-C3Eh5k7A.js (removed) 5.27 kB 🟢 -5.27 kB 🟢 -1.74 kB 🟢 -1.54 kB
assets/CloudAuthTimeoutView-D3bmDYyj.js (removed) 5.24 kB 🟢 -5.24 kB 🟢 -1.71 kB 🟢 -1.49 kB
assets/CloudAuthTimeoutView-qpNT0QoE.js (new) 5.24 kB 🔴 +5.24 kB 🔴 +1.71 kB 🔴 +1.49 kB
assets/CloudSorryContactSupportView-n5f-fGMz.js 1.97 kB 1.97 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/layout-V93lMUpe.js 500 B 500 B ⚪ 0 B ⚪ 0 B ⚪ 0 B

Status: 9 added / 9 removed

Panels & Settings — 471 kB (baseline 471 kB) • 🟢 -8 B

Configuration panels, inspectors, and settings screens

File Before After Δ Raw Δ Gzip Δ Brotli
assets/WorkspacePanel-D-86WkyO.js (new) 29.8 kB 🔴 +29.8 kB 🔴 +5.89 kB 🔴 +5.14 kB
assets/WorkspacePanel-D3l3fgTX.js (removed) 29.8 kB 🟢 -29.8 kB 🟢 -5.89 kB 🟢 -5.14 kB
assets/LegacyCreditsPanel-Cl7ZPkMk.js (new) 23.8 kB 🔴 +23.8 kB 🔴 +5.95 kB 🔴 +5.23 kB
assets/LegacyCreditsPanel-Dypxs4tz.js (removed) 23.8 kB 🟢 -23.8 kB 🟢 -5.95 kB 🟢 -5.23 kB
assets/SubscriptionPanel-BtGNpH8B.js (new) 21 kB 🔴 +21 kB 🔴 +5.04 kB 🔴 +4.44 kB
assets/SubscriptionPanel-DZf0HucS.js (removed) 21 kB 🟢 -21 kB 🟢 -5.04 kB 🟢 -4.46 kB
assets/KeybindingPanel-CHLcNIUV.js (new) 14.2 kB 🔴 +14.2 kB 🔴 +3.74 kB 🔴 +3.31 kB
assets/KeybindingPanel-CL8rE7vM.js (removed) 14.2 kB 🟢 -14.2 kB 🟢 -3.74 kB 🟢 -3.31 kB
assets/AboutPanel-BxlcZlQl.js (removed) 10.8 kB 🟢 -10.8 kB 🟢 -2.68 kB 🟢 -2.43 kB
assets/AboutPanel-Cy4u0r2o.js (new) 10.8 kB 🔴 +10.8 kB 🔴 +2.68 kB 🔴 +2.43 kB
assets/ExtensionPanel-CfGwLTGK.js (new) 10.2 kB 🔴 +10.2 kB 🔴 +2.71 kB 🔴 +2.4 kB
assets/ExtensionPanel-CNwZ6FXF.js (removed) 10.2 kB 🟢 -10.2 kB 🟢 -2.71 kB 🟢 -2.4 kB
assets/ServerConfigPanel-D_daJaPO.js (new) 7.23 kB 🔴 +7.23 kB 🔴 +2.16 kB 🔴 +1.94 kB
assets/ServerConfigPanel-vGIABPPB.js (removed) 7.23 kB 🟢 -7.23 kB 🟢 -2.17 kB 🟢 -1.93 kB
assets/UserPanel-BbOG1GPC.js (new) 6.58 kB 🔴 +6.58 kB 🔴 +1.9 kB 🔴 +1.67 kB
assets/UserPanel-eo76sKbf.js (removed) 6.58 kB 🟢 -6.58 kB 🟢 -1.9 kB 🟢 -1.68 kB
assets/refreshRemoteConfig-BOad31Fq.js (removed) 1.31 kB 🟢 -1.31 kB 🟢 -573 B 🟢 -523 B
assets/refreshRemoteConfig-D_519Atu.js (new) 1.31 kB 🔴 +1.31 kB 🔴 +571 B 🔴 +499 B
assets/config-BGVAqw9t.js (removed) 1.16 kB 🟢 -1.16 kB 🟢 -610 B 🟢 -536 B
assets/config-bWA6u4XK.js (new) 1.15 kB 🔴 +1.15 kB 🔴 +603 B 🔴 +537 B
assets/cloudRemoteConfig-DTtrUtdD.js (removed) 1.11 kB 🟢 -1.11 kB 🟢 -510 B 🟢 -451 B
assets/cloudRemoteConfig-GWlKuZco.js (new) 1.11 kB 🔴 +1.11 kB 🔴 +511 B 🔴 +446 B
assets/refreshRemoteConfig-CmoZobFi.js (removed) 169 B 🟢 -169 B 🟢 -108 B 🟢 -108 B
assets/refreshRemoteConfig-DJkUMRjT.js (new) 169 B 🔴 +169 B 🔴 +108 B 🔴 +108 B
assets/remoteConfig-B0mlVvm7.js 788 B 788 B ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-2UNjEj6k.js 32.9 kB 32.9 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-B2OMGvh7.js 31.2 kB 31.2 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-BcujOfpn.js 29.6 kB 29.6 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-BI09_t23.js 29.4 kB 29.4 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-BKamuseh.js 25.8 kB 25.8 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-BlTun9tZ.js 26.4 kB 26.4 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-CZ62uO3e.js 30.2 kB 30.2 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-DaK-NByz.js 35.2 kB 35.2 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-DaS3cSXp.js 39.4 kB 39.4 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-DWbMuaAa.js 32 kB 32 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/settings-S7pA60Hj.js 30.4 kB 30.4 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B

Status: 12 added / 12 removed

User & Accounts — 3.94 kB (baseline 3.94 kB) • ⚪ 0 B

Authentication, profile, and account management bundles

File Before After Δ Raw Δ Gzip Δ Brotli
assets/auth-4TDTLavY.js (removed) 3.54 kB 🟢 -3.54 kB 🟢 -1.24 kB 🟢 -1.05 kB
assets/auth-PIR7SV7p.js (new) 3.54 kB 🔴 +3.54 kB 🔴 +1.24 kB 🔴 +1.05 kB
assets/firebaseAuthStore-C-SO2pXp.js (removed) 217 B 🟢 -217 B 🟢 -136 B 🟢 -119 B
assets/firebaseAuthStore-CbVx6yaY.js (new) 217 B 🔴 +217 B 🔴 +136 B 🔴 +120 B
assets/auth-CgqQUStZ.js (new) 178 B 🔴 +178 B 🔴 +142 B 🔴 +136 B
assets/auth-jeJQxo11.js (removed) 178 B 🟢 -178 B 🟢 -142 B 🟢 -130 B

Status: 3 added / 3 removed

Editors & Dialogs — 2.89 kB (baseline 2.89 kB) • ⚪ 0 B

Modals, dialogs, drawers, and in-app editors

File Before After Δ Raw Δ Gzip Δ Brotli
assets/useSubscriptionDialog-Be9yAbBQ.js (removed) 2.71 kB 🟢 -2.71 kB 🟢 -1.29 kB 🟢 -1.14 kB
assets/useSubscriptionDialog-DeSk0foh.js (new) 2.71 kB 🔴 +2.71 kB 🔴 +1.28 kB 🔴 +1.14 kB
assets/useSubscriptionDialog-CC7S-YEu.js (new) 179 B 🔴 +179 B 🔴 +110 B 🔴 +100 B
assets/useSubscriptionDialog-yX0AQ4Hw.js (removed) 179 B 🟢 -179 B 🟢 -110 B 🟢 -98 B

Status: 2 added / 2 removed

UI Components — 33.7 kB (baseline 33.7 kB) • ⚪ 0 B

Reusable component library chunks

File Before After Δ Raw Δ Gzip Δ Brotli
assets/ComfyQueueButton-BX5x8VAE.js (new) 9.52 kB 🔴 +9.52 kB 🔴 +2.69 kB 🔴 +2.41 kB
assets/ComfyQueueButton-DozB5p4K.js (removed) 9.52 kB 🟢 -9.52 kB 🟢 -2.69 kB 🟢 -2.42 kB
assets/SubscribeButton-CXQr74c1.js (removed) 4.63 kB 🟢 -4.63 kB 🟢 -1.57 kB 🟢 -1.39 kB
assets/SubscribeButton-DHtXuvoL.js (new) 4.63 kB 🔴 +4.63 kB 🔴 +1.57 kB 🔴 +1.39 kB
assets/cloudFeedbackTopbarButton--eXa96VJ.js (removed) 1.24 kB 🟢 -1.24 kB 🟢 -675 B 🟢 -573 B
assets/cloudFeedbackTopbarButton-DFHdQiwu.js (new) 1.24 kB 🔴 +1.24 kB 🔴 +674 B 🔴 +573 B
assets/ComfyQueueButton-DVF4eeL2.js (removed) 181 B 🟢 -181 B 🟢 -118 B 🟢 -119 B
assets/ComfyQueueButton-rux3csJi.js (new) 181 B 🔴 +181 B 🔴 +118 B 🔴 +116 B
assets/Button-Bb_i0j7c.js 3.82 kB 3.82 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/CloudBadge-XMwjdY2I.js 1.85 kB 1.85 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/TopbarBadge-qACg_vGT.js 8.36 kB 8.36 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/UserAvatar-D80lITos.js 1.73 kB 1.73 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetButton-DSv9NFvF.js 2.41 kB 2.41 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B

Status: 4 added / 4 removed

Data & Services — 2.7 MB (baseline 2.7 MB) • 🔴 +1 B

Stores, services, APIs, and repositories

File Before After Δ Raw Δ Gzip Δ Brotli
assets/dialogService-D7CwYshr.js (new) 2 MB 🔴 +2 MB 🔴 +424 kB 🔴 +323 kB
assets/dialogService-DVbDiqVq.js (removed) 2 MB 🟢 -2 MB 🟢 -424 kB 🟢 -323 kB
assets/api-Bi0niRHP.js (new) 673 kB 🔴 +673 kB 🔴 +149 kB 🔴 +118 kB
assets/api-C_r1I4zZ.js (removed) 673 kB 🟢 -673 kB 🟢 -149 kB 🟢 -118 kB
assets/releaseStore-DJYqH3jA.js (new) 8.91 kB 🔴 +8.91 kB 🔴 +2.4 kB 🔴 +2.12 kB
assets/releaseStore-nbhDWfEo.js (removed) 8.91 kB 🟢 -8.91 kB 🟢 -2.4 kB 🟢 -2.12 kB
assets/keybindingService-BsJuZu5b.js (new) 6.78 kB 🔴 +6.78 kB 🔴 +1.74 kB 🔴 +1.52 kB
assets/keybindingService-v8pylEaE.js (removed) 6.78 kB 🟢 -6.78 kB 🟢 -1.74 kB 🟢 -1.52 kB
assets/bootstrapStore-B7Jyx5oV.js (new) 2.69 kB 🔴 +2.69 kB 🔴 +1.03 kB 🔴 +957 B
assets/bootstrapStore-Clsw-SGJ.js (removed) 2.69 kB 🟢 -2.69 kB 🟢 -1.03 kB 🟢 -951 B
assets/userStore-C6mg9Szp.js (removed) 2.16 kB 🟢 -2.16 kB 🟢 -810 B 🟢 -723 B
assets/userStore-CX9_oLag.js (new) 2.16 kB 🔴 +2.16 kB 🔴 +809 B 🔴 +725 B
assets/audioService-Tf6rDKff.js (removed) 2.03 kB 🟢 -2.03 kB 🟢 -932 B 🟢 -811 B
assets/audioService-YgcAU0uw.js (new) 2.03 kB 🔴 +2.03 kB 🔴 +929 B 🔴 +816 B
assets/releaseStore-BStnt_0p.js (new) 140 B 🔴 +140 B 🔴 +106 B 🔴 +104 B
assets/releaseStore-D5xg2KL8.js (removed) 140 B 🟢 -140 B 🟢 -106 B 🟢 -102 B
assets/serverConfigStore-DOoqLe5c.js 2.64 kB 2.64 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B

Status: 8 added / 8 removed

Utilities & Hooks — 25.3 kB (baseline 25.3 kB) • ⚪ 0 B

Helpers, composables, and utility bundles

File Before After Δ Raw Δ Gzip Δ Brotli
assets/useErrorHandling-BbJ-oyBC.js (removed) 5.21 kB 🟢 -5.21 kB 🟢 -1.53 kB 🟢 -1.34 kB
assets/useErrorHandling-CCTHSCG8.js (new) 5.21 kB 🔴 +5.21 kB 🔴 +1.53 kB 🔴 +1.37 kB
assets/useWorkspaceUI-CeXpQ9iS.js (new) 3.42 kB 🔴 +3.42 kB 🔴 +976 B 🔴 +838 B
assets/useWorkspaceUI-D2-axo1E.js (removed) 3.42 kB 🟢 -3.42 kB 🟢 -975 B 🟢 -840 B
assets/useSubscriptionActions-BbOW82KB.js (removed) 2.22 kB 🟢 -2.22 kB 🟢 -872 B 🟢 -761 B
assets/useSubscriptionActions-BJ_cAmzM.js (new) 2.22 kB 🔴 +2.22 kB 🔴 +869 B 🔴 +762 B
assets/subscriptionCheckoutUtil-D7LsdMQ6.js (new) 2.03 kB 🔴 +2.03 kB 🔴 +871 B 🔴 +763 B
assets/subscriptionCheckoutUtil-w5JWv6TR.js (removed) 2.03 kB 🟢 -2.03 kB 🟢 -875 B 🟢 -767 B
assets/useSubscriptionCredits-C6KvKmNI.js (removed) 1.39 kB 🟢 -1.39 kB 🟢 -600 B 🟢 -529 B
assets/useSubscriptionCredits-CvHMimbo.js (new) 1.39 kB 🔴 +1.39 kB 🔴 +598 B 🔴 +529 B
assets/audioUtils-CO-umPJm.js (new) 970 B 🔴 +970 B 🔴 +547 B 🔴 +459 B
assets/audioUtils-DobJK1zu.js (removed) 970 B 🟢 -970 B 🟢 -548 B 🟢 -461 B
assets/useCurrentUser-BcUWASEh.js (removed) 145 B 🟢 -145 B 🟢 -114 B 🟢 -99 B
assets/useCurrentUser-C2bVs888.js (new) 145 B 🔴 +145 B 🔴 +114 B 🔴 +100 B
assets/_plugin-vue_export-helper-DuK_Fly3.js 467 B 467 B ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/colorUtil-GMAsfHxw.js 7.2 kB 7.2 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/markdownRendererUtil-ivqHoiOs.js 1.78 kB 1.78 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/tailwindUtil-CJjrIEVR.js 488 B 488 B ⚪ 0 B ⚪ 0 B ⚪ 0 B

Status: 7 added / 7 removed

Vendor & Third-Party — 10.7 MB (baseline 10.7 MB) • ⚪ 0 B

External libraries and shared vendor chunks

File Before After Δ Raw Δ Gzip Δ Brotli
assets/vendor-chart-DHGfk3hn.js 408 kB 408 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/vendor-other-jpGqhHNG.js 4.1 MB 4.1 MB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/vendor-primevue-4Jj8eU28.js 3.04 MB 3.04 MB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/vendor-reka-ui-aCG649nF.js 263 kB 263 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/vendor-three-CERwhPwK.js 1.83 MB 1.83 MB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/vendor-tiptap-BxrEVL6s.js 650 kB 650 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/vendor-vue-Dwii0E-t.js 13.6 kB 13.6 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/vendor-xterm-IX6P8SWv.js 398 kB 398 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
Other — 7.05 MB (baseline 7.05 MB) • 🟢 -198 B

Bundles that do not match a named category

File Before After Δ Raw Δ Gzip Δ Brotli
assets/core-BCfYfpNJ.js (removed) 180 kB 🟢 -180 kB 🟢 -43.3 kB 🟢 -36.2 kB
assets/core-CLlA2RDi.js (new) 180 kB 🔴 +180 kB 🔴 +43.3 kB 🔴 +36.2 kB
assets/WidgetSelect-8xUw4V3m.js (removed) 51 kB 🟢 -51 kB 🟢 -11.3 kB 🟢 -9.81 kB
assets/WidgetSelect-DrL8sq6W.js (new) 51 kB 🔴 +51 kB 🔴 +11.2 kB 🔴 +9.81 kB
assets/Load3DControls-BspFfC8N.js (new) 35.9 kB 🔴 +35.9 kB 🔴 +5.86 kB 🔴 +5.08 kB
assets/Load3DControls-nh_kOAsB.js (removed) 35.9 kB 🟢 -35.9 kB 🟢 -5.87 kB 🟢 -5.08 kB
assets/SubscriptionRequiredDialogContent-Cy4XAuja.js (new) 28.7 kB 🔴 +28.7 kB 🔴 +6.79 kB 🔴 +5.91 kB
assets/SubscriptionRequiredDialogContent-zahUsYeW.js (removed) 28.7 kB 🟢 -28.7 kB 🟢 -6.79 kB 🟢 -5.92 kB
assets/CurrentUserPopoverWorkspace-0MSgc9rO.js (removed) 22.2 kB 🟢 -22.2 kB 🟢 -4.99 kB 🟢 -4.42 kB
assets/CurrentUserPopoverWorkspace-1ifNPk4e.js (new) 22.2 kB 🔴 +22.2 kB 🔴 +4.99 kB 🔴 +4.42 kB
assets/Load3D-D1sQCqfI.js (removed) 19.2 kB 🟢 -19.2 kB 🟢 -4.37 kB 🟢 -3.84 kB
assets/Load3D-D8n1ZMhK.js (new) 19.2 kB 🔴 +19.2 kB 🔴 +4.37 kB 🔴 +3.85 kB
assets/WidgetRecordAudio-CWuAvpOh.js (new) 18.3 kB 🔴 +18.3 kB 🔴 +4.97 kB 🔴 +4.44 kB
assets/WidgetRecordAudio-yzSispgO.js (removed) 18.3 kB 🟢 -18.3 kB 🟢 -4.97 kB 🟢 -4.44 kB
assets/WidgetInputNumber-BMU5owxR.js (removed) 18.3 kB 🟢 -18.3 kB 🟢 -4.51 kB 🟢 -4.02 kB
assets/WidgetInputNumber-CaYwHxYR.js (new) 18.3 kB 🔴 +18.3 kB 🔴 +4.51 kB 🔴 +4.02 kB
assets/SubscriptionPanelContentWorkspace-BQtaoRIs.js (new) 18.2 kB 🔴 +18.2 kB 🔴 +4.47 kB 🔴 +3.89 kB
assets/SubscriptionPanelContentWorkspace-CiF1PdaS.js (removed) 18.2 kB 🟢 -18.2 kB 🟢 -4.47 kB 🟢 -3.9 kB
assets/WidgetImageCrop-BYFzMYMN.js (removed) 17.1 kB 🟢 -17.1 kB 🟢 -4.14 kB 🟢 -3.61 kB
assets/WidgetImageCrop-pUWeynF7.js (new) 17.1 kB 🔴 +17.1 kB 🔴 +4.14 kB 🔴 +3.62 kB
assets/PanelTemplate-BeINBrWO.js (new) 16.2 kB 🔴 +16.2 kB 🔴 +5.45 kB 🔴 +4.8 kB
assets/PanelTemplate-Co4su8q4.js (removed) 16.2 kB 🟢 -16.2 kB 🟢 -5.45 kB 🟢 -4.8 kB
assets/AudioPreviewPlayer-BNGalYHV.js (new) 10.8 kB 🔴 +10.8 kB 🔴 +2.98 kB 🔴 +2.65 kB
assets/AudioPreviewPlayer-CEtNHZZK.js (removed) 10.8 kB 🟢 -10.8 kB 🟢 -2.98 kB 🟢 -2.65 kB
assets/InviteMemberDialogContent-Dt8UaX3y.js (new) 8.36 kB 🔴 +8.36 kB 🔴 +2.5 kB 🔴 +2.17 kB
assets/InviteMemberDialogContent-vcSoY9b1.js (removed) 8.36 kB 🟢 -8.36 kB 🟢 -2.5 kB 🟢 -2.17 kB
assets/WidgetWithControl-CiBV6nnS.js (removed) 8.07 kB 🟢 -8.07 kB 🟢 -2.68 kB 🟢 -2.41 kB
assets/WidgetWithControl-DIQvrroj.js (new) 8.07 kB 🔴 +8.07 kB 🔴 +2.68 kB 🔴 +2.41 kB
assets/CreateWorkspaceDialogContent-C6cHexik.js (removed) 5.93 kB 🟢 -5.93 kB 🟢 -1.93 kB 🟢 -1.68 kB
assets/CreateWorkspaceDialogContent-CU1s3sac.js (new) 5.93 kB 🔴 +5.93 kB 🔴 +1.93 kB 🔴 +1.68 kB
assets/EditWorkspaceDialogContent-CSGrTHw9.js (removed) 5.7 kB 🟢 -5.7 kB 🟢 -1.88 kB 🟢 -1.65 kB
assets/EditWorkspaceDialogContent-EC2OO8y8.js (new) 5.7 kB 🔴 +5.7 kB 🔴 +1.88 kB 🔴 +1.64 kB
assets/ValueControlPopover-BCox-Olh.js (removed) 5.17 kB 🟢 -5.17 kB 🟢 -1.68 kB 🟢 -1.5 kB
assets/ValueControlPopover-Be9vpDA2.js (new) 5.17 kB 🔴 +5.17 kB 🔴 +1.68 kB 🔴 +1.5 kB
assets/DeleteWorkspaceDialogContent-_sq4NSV1.js (new) 4.59 kB 🔴 +4.59 kB 🔴 +1.56 kB 🔴 +1.35 kB
assets/DeleteWorkspaceDialogContent-CEaGAg6v.js (removed) 4.59 kB 🟢 -4.59 kB 🟢 -1.56 kB 🟢 -1.35 kB
assets/LeaveWorkspaceDialogContent-4cC3xEbm.js (new) 4.41 kB 🔴 +4.41 kB 🔴 +1.5 kB 🔴 +1.3 kB
assets/LeaveWorkspaceDialogContent-Bb0iaH_8.js (removed) 4.41 kB 🟢 -4.41 kB 🟢 -1.5 kB 🟢 -1.3 kB
assets/RemoveMemberDialogContent-6EFP58_a.js (removed) 4.38 kB 🟢 -4.38 kB 🟢 -1.45 kB 🟢 -1.26 kB
assets/RemoveMemberDialogContent-RbmJ4NP4.js (new) 4.38 kB 🔴 +4.38 kB 🔴 +1.45 kB 🔴 +1.26 kB
assets/RevokeInviteDialogContent-CKPbEPnO.js (new) 4.29 kB 🔴 +4.29 kB 🔴 +1.47 kB 🔴 +1.29 kB
assets/RevokeInviteDialogContent-DgCK-x6z.js (removed) 4.29 kB 🟢 -4.29 kB 🟢 -1.47 kB 🟢 -1.29 kB
assets/GlobalToast-4hZU5po-.js (removed) 3.05 kB 🟢 -3.05 kB 🟢 -1.1 kB 🟢 -938 B
assets/GlobalToast-BWVHwgzQ.js (new) 3.05 kB 🔴 +3.05 kB 🔴 +1.1 kB 🔴 +939 B
assets/SubscribeToRun-B0fSgece.js (removed) 2.96 kB 🟢 -2.96 kB 🟢 -1.15 kB 🟢 -1.01 kB
assets/SubscribeToRun-DwzBS83L.js (new) 2.96 kB 🔴 +2.96 kB 🔴 +1.15 kB 🔴 +1.01 kB
assets/cloudSessionCookie-BpzpxQ3S.js (new) 2.94 kB 🔴 +2.94 kB 🔴 +929 B 🔴 +801 B
assets/cloudSessionCookie-peCuwKdE.js (removed) 2.94 kB 🟢 -2.94 kB 🟢 -929 B 🟢 -806 B
assets/BaseViewTemplate-D2o7tGNp.js (new) 2.42 kB 🔴 +2.42 kB 🔴 +1.04 kB 🔴 +942 B
assets/BaseViewTemplate-DF21NACD.js (removed) 2.42 kB 🟢 -2.42 kB 🟢 -1.04 kB 🟢 -949 B
assets/CloudRunButtonWrapper-86S6P62E.js (removed) 1.79 kB 🟢 -1.79 kB 🟢 -645 B 🟢 -562 B
assets/CloudRunButtonWrapper-CYtfAbQm.js (new) 1.79 kB 🔴 +1.79 kB 🔴 +646 B 🔴 +566 B
assets/cloudBadges-DZoHQweR.js (new) 1.08 kB 🔴 +1.08 kB 🔴 +535 B 🔴 +477 B
assets/cloudBadges-mkeSSGUZ.js (removed) 1.08 kB 🟢 -1.08 kB 🟢 -537 B 🟢 -479 B
assets/graphHasMissingNodes-DS6cqUlJ.js (removed) 1.06 kB 🟢 -1.06 kB 🟢 -462 B 🟢 -416 B
assets/graphHasMissingNodes-iaYapfAo.js (new) 1.06 kB 🔴 +1.06 kB 🔴 +460 B 🔴 +426 B
assets/cloudSubscription-BWOuVpDc.js (new) 976 B 🔴 +976 B 🔴 +466 B 🔴 +398 B
assets/cloudSubscription-DOXXgcoz.js (removed) 976 B 🟢 -976 B 🟢 -466 B 🟢 -398 B
assets/nightlyBadges-CFf9cLtf.js (new) 595 B 🔴 +595 B 🔴 +353 B 🔴 +310 B
assets/nightlyBadges-jCgvnDcJ.js (removed) 595 B 🟢 -595 B 🟢 -354 B 🟢 -314 B
assets/SubscriptionPanelContentWorkspace-DiIaxvls.js (removed) 266 B 🟢 -266 B 🟢 -136 B 🟢 -109 B
assets/SubscriptionPanelContentWorkspace-W-r1sWbn.js (new) 266 B 🔴 +266 B 🔴 +136 B 🔴 +116 B
assets/WidgetInputNumber-B2kDU337.js (new) 186 B 🔴 +186 B 🔴 +119 B 🔴 +109 B
assets/WidgetInputNumber-BWGWjZI_.js (removed) 186 B 🟢 -186 B 🟢 -119 B 🟢 -110 B
assets/WidgetLegacy-C0VmVKwE.js (new) 164 B 🔴 +164 B 🔴 +125 B 🔴 +117 B
assets/WidgetLegacy-KkbdgGTD.js (removed) 164 B 🟢 -164 B 🟢 -125 B 🟢 -121 B
assets/Load3D-CqnoPB6U.js (removed) 131 B 🟢 -131 B 🟢 -107 B 🟢 -108 B
assets/Load3D-jlghRd5D.js (new) 131 B 🔴 +131 B 🔴 +107 B 🔴 +108 B
assets/auto-DWs2ctGL.js 1.73 kB 1.73 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-BEw5ErI4.js 18.5 kB 18.5 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-BGeHkplA.js 17.9 kB 17.9 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-BV0l36Iz.js 17.2 kB 17.2 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-C_Y3D6Cn.js 17.8 kB 17.8 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-C6piRza5.js 19.3 kB 19.3 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-Cf8Zq1td.js 18.8 kB 18.8 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-CiziP3Xs.js 18 kB 18 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-D1595tOr.js 19.3 kB 19.3 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-DXauvccL.js 20.6 kB 20.6 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-P5QCEfZc.js 18 kB 18 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/commands-WbYP_D61.js 17 kB 17 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/i18n-BfSNaAqr.js 188 B 188 B ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/i18n-CU81Mahr.js 496 kB 496 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/LazyImage-DHwPdKGO.js 14.1 kB 14.1 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-12Ugs8uH.js 113 kB 113 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-bK51E1AF.js 133 kB 133 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-BpNRRXRJ.js 151 kB 151 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-c-Kg1DWL.js 126 kB 126 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-C16qe5Pa.js 144 kB 144 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-C2P63O3F.js 126 kB 126 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-C5b27iBR.js 112 kB 112 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-CcswxyNG.js 173 kB 173 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-D6eu0Wen.js 128 kB 128 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-DbxHumst.js 130 kB 130 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/main-DKTrxQrQ.js 155 kB 155 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/Media3DTop-DUmUhXD6.js 2.38 kB 2.38 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/MediaAudioTop-CD66_Mw_.js 2 kB 2 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/MediaImageTop-Bqe7yvm_.js 2.34 kB 2.34 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/MediaVideoTop-De3MzVmp.js 2.82 kB 2.82 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/mixpanel.module-CC2-PIpB.js 143 B 143 B ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-B0UaQKt6.js 363 kB 363 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-B68z80AD.js 413 kB 413 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-Bg1UEeRw.js 448 kB 448 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-CicFSATk.js 339 kB 339 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-CinCueZ7.js 373 kB 373 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-DgzjkU5p.js 366 kB 366 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-DKHHBXVW.js 369 kB 369 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-Dn1Haq99.js 342 kB 342 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-DxR-7ogK.js 383 kB 383 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-qCfy7PeV.js 412 kB 412 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/nodeDefs-xDY-sSQw.js 369 kB 369 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/OBJLoader2WorkerModule-DTMpvldF.js 109 kB 109 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/previousFullPath-CmezY7As.js 838 B 838 B ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/rolldown-runtime-cVp-94Rc.js 1.96 kB 1.96 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/Slider-D4lsf6Ob.js 4.21 kB 4.21 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/widget-BJiJuR5i.js 518 B 518 B ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetBoundingBox-CUtab2CB.js 4.71 kB 4.71 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetBoundingBox-D79nBMxa.js 186 B 186 B ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetChart-CiXfBVBH.js 2.79 kB 2.79 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetColorPicker-BxNqMlFv.js 3.71 kB 3.71 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetGalleria-DDD96zwa.js 4.57 kB 4.57 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetImageCompare-A6pZMGtc.js 3.79 kB 3.79 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetInputText-DSMUKRnt.js 2.58 kB 2.58 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetLayoutField-MDImyvc3.js 2.7 kB 2.7 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetMarkdown-C95PPn5g.js 3.22 kB 3.22 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/widgetPropFilter-ERx8czR8.js 1.31 kB 1.31 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetTextarea-CV3BoahN.js 3.87 kB 3.87 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/WidgetToggleSwitch-ZdaYkxkD.js 3.26 kB 3.26 kB ⚪ 0 B ⚪ 0 B ⚪ 0 B
assets/widgetTypes-KPj-zM0O.js 573 B 573 B ⚪ 0 B ⚪ 0 B ⚪ 0 B

Status: 34 added / 34 removed

DrJKL and others added 6 commits January 28, 2026 13:17
Pin all third-party actions to full-length commit SHAs instead of
mutable tags for supply chain security. Tags can be updated by
maintainers, potentially injecting malicious code with access to
repository secrets.

Actions pinned:
- pnpm/action-setup (v4.2.0)
- peter-evans/create-pull-request (v8.1.0)
- peter-evans/find-comment (v4.0.0)
- peter-evans/create-or-update-comment (v5.0.0)
- pypa/gh-action-pypi-publish (v1.12.4)
- dawidd6/action-download-artifact (v12)
- juliangruber/read-file-action (v1.1.7)
- actions-cool/maintain-one-comment (v3.2.0)
- shimataro/ssh-key-action (v2.7.0)
- chromaui/action (v13)
- anthropics/claude-code-action (v1.0)

Each pinned action includes a version comment for human readability.

Amp-Thread-ID: https://ampcode.com/threads/T-019c0675-10a1-700b-a684-e39adde310e7
Co-authored-by: Amp <amp@ampcode.com>
Validates that all third-party GitHub Actions are pinned to commit SHAs on PRs that modify workflow files.

Amp-Thread-ID: https://ampcode.com/threads/T-019c0675-10a1-700b-a684-e39adde310e7
Co-authored-by: Amp <amp@ampcode.com>
@DrJKL
DrJKL requested a review from AustinMroz January 28, 2026 22:12
uses: actions/cache/restore@v4
# Cache tool outputs (restore on start, save on completion)
- name: Cache tool outputs
uses: actions/cache@v5

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this line changed the meaning of code

maybe one of:

  1. explain why still it works after cache/restore=> cache
  2. move to another PR to keep this PR do only tidy work?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have migrated from actions/cache save+restore , to artifact upload/download in this Commit

3372f455c#diff-13dfc4899b42a67d2bcdbffdadd0a684eb2002473c705acd75065f0dfe6a32d3L34

so its prob safe to remove the restore step completely here :D , as we are not saving any cache here, its identical

WDYT @DrJKL

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread .pinact.yaml

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

where do pinact run?

  1. do we need to pnpm install -d or add to package.json?
  2. does CI runs it?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You can install it locally, or it'll run as an action when the actions/workflows or the config are changed (to validate, not to update)

@snomiao snomiao Jan 29, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

got it!, it runs here

.github/workflows/ci-validate-action-pins.yaml

Comment thread .pinact.yaml
@@ -0,0 +1,24 @@
# pinact configuration
# https://github.com/suzuki-shunsuke/pinact

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

got it!

it runs by .github/workflows/ci-validate-action-pins.yaml

@snomiao
snomiao self-requested a review January 29, 2026 01:27
@DrJKL
DrJKL requested a review from christian-byrne January 29, 2026 02:11
@DrJKL
DrJKL marked this pull request as ready for review January 29, 2026 04:26
@DrJKL
DrJKL requested a review from a team as a code owner January 29, 2026 04:26
@dosubot dosubot Bot added the size:L This PR changes 100-499 lines, ignoring generated files. label Jan 29, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/actions/setup-comfyui-server/action.yaml (1)

29-32: Update the stale checkout version in the error message.
The action uses actions/checkout@v6 (line 19), but the error message at line 31 still references v5. Remove the version to keep the message version-agnostic and prevent future drift.

🔧 Proposed fix
-        echo "::error::Please ensure you have run 'actions/checkout@v5' before calling this action."
+        echo "::error::Please ensure you have run 'actions/checkout' before calling this action."
🤖 Fix all issues with AI agents
In @.github/workflows/ci-tests-e2e-forks.yaml:
- Around line 33-34: The workflow upgrade to actions/checkout@v6,
actions/github-script@v8, and actions/download-artifact@v7 introduces breaking
changes (credentials now stored under $RUNNER_TEMP and Node 24 runtime) so
update CI to either pin compatible action versions or ensure runners meet
minimum versions and remove any logic that parses .git/config for auth;
specifically, review uses of actions/checkout@v6, actions/github-script@v8, and
actions/download-artifact@v7, replace or pin them to earlier compatible tags if
you cannot guarantee runner v2.329.0+ (for checkout) and v2.327.1+ (for
github-script/download-artifact), and refactor any scripts that read .git/config
to instead read credentials from the new $RUNNER_TEMP location or use GitHub
Actions-provided environment variables for authentication.

In @.github/workflows/ci-yaml-validation.yaml:
- Around line 20-25: The workflow uses actions/checkout@v6 and
actions/setup-python@v6 which introduce breaking changes; either pin to the last
known-compatible releases (e.g., replace actions/checkout@v6 with
actions/checkout@v5 and actions/setup-python@v4) or ensure the CI runner is
upgraded to the required versions (GitHub Actions Runner v2.329.0+ for checkout
and v2.327.1+ for setup-python) and adapt checkout usage (e.g., explicitly set
persist-credentials if your tools expect credentials in .git/config). Update the
two uses: the lines referencing actions/checkout@v6 and actions/setup-python@v6
accordingly, and add a note or check in your CI configuration to verify runner
version if you choose to keep v6.

In @.github/workflows/release-biweekly-comfyui.yaml:
- Around line 63-84: The Setup Node.js steps using actions/setup-node@v6 are
missing explicit pnpm caching; update the Setup Node.js `with:` blocks (the
steps named "Setup Node.js" in the resolve-version job and the create-comfyui-pr
job) to include `cache: pnpm` alongside the existing `node-version` key so pnpm
dependencies are cached by the action.

In @.github/workflows/release-draft-create.yaml:
- Around line 73-76: The workflow step named "Create release" (id
create_release) currently uses the floating tag softprops/action-gh-release@v2;
replace that floating tag with the action's fully-pinned commit SHA
(softprops/action-gh-release@<full-commit-sha>) and add the matching version
comment style used across the repo (e.g., a trailing comment indicating the
release tag/semver) so the step is pinned to an exact commit and conforms to the
repository's pinning policy.

Comment on lines 33 to +34
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v6

@coderabbitai coderabbitai Bot Jan 29, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🌐 Web query:

actions/checkout v6 release notes breaking changes

💡 Result:

actions/checkout v6 — breaking/behavior-changing notes

  • Credentials are no longer written into .git/config when persist-credentials: true. v6 persists credentials to a separate file under $RUNNER_TEMP instead (security hardening). This can break workflows/scripts that expect to read auth from .git/config (e.g., custom tooling that parses config rather than just running git fetch/push). [1][2]
  • Runner requirement for Docker container actions: If you run authenticated git commands from a Docker container action, you need GitHub Actions Runner v2.329.0+. (Workflows that rely on this on older/self-hosted runners may fail.) [1]
  • General upgrade note: The project’s stated intent is that no workflow changes are required for normal git usage (git fetch, git push, etc. should still work). [1]

Sources:
[1] actions/checkout README (“Checkout v6 / What’s new”)
[2] v6.0.0 release notes (includes “Persist creds to a separate file”)


🌐 Web query:

actions/github-script v8 release breaking changes

💡 Result:

actions/github-script@v8 has one explicit breaking change:

  • Runtime bumped to Node.js 24 (from Node.js 20 in v7). Any breaking changes between Node 20 → 24 can affect your script (language/runtime behavior and bundled dependencies). [1][2]
  • Minimum required GitHub Actions runner version: v2.327.1 (relevant for self-hosted runners; upgrade if you pin runner versions). [1][2]

No other v8-specific breaking API surface changes are called out in the project’s breaking-changes notes beyond the Node 24 runtime/runner requirement. [1]


🌐 Web query:

actions/download-artifact v7 release breaking changes

💡 Result:

For actions/download-artifact@v7, the breaking change called out in the release docs is:

  • Runtime upgrade to Node.js 24 (runs.using: node24). This requires GitHub Actions Runner >= 2.327.1—so older self-hosted runners must be updated before upgrading to @v7, or the action can fail to run. [1]

Source: [1]


Verify GitHub Actions version upgrades for breaking changes.

The version bumps have confirmed breaking changes:

  • actions/checkout@v6: Credentials are no longer stored in .git/config; they're now persisted to a separate file under $RUNNER_TEMP. Workflows or scripts that parse .git/config for authentication will break. Also requires runner v2.329.0+ for authenticated git commands from Docker containers.
  • actions/github-script@v8: Runtime bumped to Node.js 24 (from v20). This can introduce breaking changes in your script block; requires runner v2.327.1+.
  • actions/download-artifact@v7: Runtime upgraded to Node.js 24; requires runner v2.327.1+.

Ensure your GitHub Actions runners meet the minimum version requirements and that workflows do not depend on credential storage in .git/config.

🤖 Prompt for AI Agents
In @.github/workflows/ci-tests-e2e-forks.yaml around lines 33 - 34, The workflow
upgrade to actions/checkout@v6, actions/github-script@v8, and
actions/download-artifact@v7 introduces breaking changes (credentials now stored
under $RUNNER_TEMP and Node 24 runtime) so update CI to either pin compatible
action versions or ensure runners meet minimum versions and remove any logic
that parses .git/config for auth; specifically, review uses of
actions/checkout@v6, actions/github-script@v8, and actions/download-artifact@v7,
replace or pin them to earlier compatible tags if you cannot guarantee runner
v2.329.0+ (for checkout) and v2.327.1+ (for github-script/download-artifact),
and refactor any scripts that read .git/config to instead read credentials from
the new $RUNNER_TEMP location or use GitHub Actions-provided environment
variables for authentication.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's good.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@DrJKL, understood! I've noted that you're aware of the breaking changes in the upgraded actions and they're acceptable for this workflow.


🧠 Learnings used
Learnt from: Myestery
Repo: Comfy-Org/ComfyUI_frontend PR: 7422
File: .github/workflows/pr-update-playwright-expectations.yaml:131-135
Timestamp: 2025-12-12T23:02:37.473Z
Learning: In the `.github/workflows/pr-update-playwright-expectations.yaml` workflow in the Comfy-Org/ComfyUI_frontend repository, the snapshot update process is intentionally scoped to only add and update snapshot images. Deletions of snapshot files are handled explicitly outside this workflow and should not be suggested as part of this automation.

Comment on lines +20 to 25
- uses: actions/checkout@v6

- name: Set up Python
uses: actions/setup-python@v5
uses: actions/setup-python@v6
with:
python-version: '3.x'

@coderabbitai coderabbitai Bot Jan 29, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🌐 Web query:

actions/checkout v6 release notes breaking changes

💡 Result:

actions/checkout@v6 (released Nov 20, 2025 as v6.0.0) is primarily a credentials-handling change. (github.com)

Breaking / behavior changes to be aware of

  • persist-credentials no longer writes auth directly into .git/config. Credentials are now stored in a separate file under $RUNNER_TEMP (improved security). This can break workflows/tools that expect to read credentials from .git/config or copy/inspect the repo’s .git/config to propagate auth. (github.com)
  • Docker container actions + authenticated git commands: if you run authenticated git commands from inside a Docker container action, you now need GitHub Actions Runner v2.329.0+ for auth to work as expected. (github.com)

What is not breaking for most users

  • Normal host-runner git commands (e.g., git fetch, git push) generally continue to work without workflow changes, because the action configures git so credentials are still picked up automatically. (github.com)

Citations:


🌐 Web query:

actions/setup-python v6 release notes breaking changes

💡 Result:

actions/setup-python v6 (v6.0.0) breaking change

  • Action runtime upgraded from Node.js 20 to Node.js 24 (breaking change). [1][2]
  • Runner requirement: your GitHub Actions runner must be v2.327.1 or later for compatibility with the Node 24-based action. [1][2]

Release notes: [1]
Docs “Breaking changes in V6”: [2][3]

Sources:
[1] actions/setup-python GitHub Releases (v6.0.0) (github.com)
[2] actions/setup-python README (“Breaking changes in V6”) (github.com)
[3] GitHub Marketplace listing (“Breaking changes in V6”) (github.com)

Citations:


Address breaking changes in actions/checkout@v6 and actions/setup-python@v6.

Both v6 releases introduce breaking changes requiring attention:

  • actions/checkout@v6: Credentials handling changed—persist-credentials no longer writes to .git/config but uses a separate file in $RUNNER_TEMP. This breaks workflows or tools that inspect .git/config for credentials. Additionally, Docker container actions using authenticated git commands require GitHub Actions Runner v2.329.0+.

  • actions/setup-python@v6: Runtime upgraded from Node.js 20 to Node.js 24. Requires GitHub Actions runner v2.327.1 or later for compatibility.

Ensure your GitHub Actions runner version meets these requirements (v2.329.0+ for safety). For non-Docker host-runner workflows, normal git commands generally continue to work, but verify credentials flow is not disrupted.

🤖 Prompt for AI Agents
In @.github/workflows/ci-yaml-validation.yaml around lines 20 - 25, The workflow
uses actions/checkout@v6 and actions/setup-python@v6 which introduce breaking
changes; either pin to the last known-compatible releases (e.g., replace
actions/checkout@v6 with actions/checkout@v5 and actions/setup-python@v4) or
ensure the CI runner is upgraded to the required versions (GitHub Actions Runner
v2.329.0+ for checkout and v2.327.1+ for setup-python) and adapt checkout usage
(e.g., explicitly set persist-credentials if your tools expect credentials in
.git/config). Update the two uses: the lines referencing actions/checkout@v6 and
actions/setup-python@v6 accordingly, and add a note or check in your CI
configuration to verify runner version if you choose to keep v6.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're fine.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@DrJKL, understood! If you've verified the runner versions are compatible or the credential handling changes don't impact your workflows, then you're all set. 👍

(\_/)
(•_•)
/>📋

🧠 Learnings used
Learnt from: Myestery
Repo: Comfy-Org/ComfyUI_frontend PR: 7422
File: .github/workflows/pr-update-playwright-expectations.yaml:131-135
Timestamp: 2025-12-12T23:02:37.473Z
Learning: In the `.github/workflows/pr-update-playwright-expectations.yaml` workflow in the Comfy-Org/ComfyUI_frontend repository, the snapshot update process is intentionally scoped to only add and update snapshot images. Deletions of snapshot files are handled explicitly outside this workflow and should not be suggested as part of this automation.

Comment on lines 63 to 84
- name: Checkout ComfyUI_frontend
uses: actions/checkout@v5
uses: actions/checkout@v6
with:
fetch-depth: 0
path: frontend

- name: Checkout ComfyUI (sparse)
uses: actions/checkout@v5
uses: actions/checkout@v6
with:
repository: Comfy-Org/ComfyUI
sparse-checkout: |
requirements.txt
path: comfyui

- name: Install pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
with:
version: 10

- name: Setup Node.js
uses: actions/setup-node@v4
uses: actions/setup-node@v6
with:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

cat -n .github/workflows/release-biweekly-comfyui.yaml | sed -n '55,90p'

Repository: Comfy-Org/ComfyUI_frontend

Length of output: 1434


🏁 Script executed:

cat -n .github/workflows/release-biweekly-comfyui.yaml | sed -n '165,180p'

Repository: Comfy-Org/ComfyUI_frontend

Length of output: 795


🌐 Web query:

actions/checkout v6 release github

💡 Result:

  • actions/checkout@v6 was released as v6.0.0 (dated “20 Nov”). Key v6 change: improved credential security—when persist-credentials: true, credentials are stored in a separate file under $RUNNER_TEMP instead of .git/config; most workflows don’t need changes. Also, running authenticated git commands from a Docker container action requires Actions Runner v2.329.0+. [1]
  • Most recent v6 patch release shown on GitHub Releases is v6.0.2 (dated “09 Jan”), with changes including: adding orchestration_id to the git user-agent when ACTIONS_ORCHESTRATION_ID is set, and fixing tag handling to preserve annotations / explicit fetch-tags. [2]

Sources: [1] actions/checkout repository (“Checkout v6 / What’s new”), [2] actions/checkout Releases page (v6.0.2 notes).


🌐 Web query:

actions/setup-node v6 release

💡 Result:

actions/setup-node v6.0.0 was released October 14, 2025. Its key breaking change is that automatic caching is now limited to npm (workflows/docs updated accordingly); Yarn/pnpm caching must be explicitly configured (e.g., via the cache input). [1][2][4]

As of January 15, 2026, the latest v6 release is v6.2.0, which is primarily documentation updates plus a dependency update (upgrade @actions/cache to v5.0.1). [3]


🌐 Web query:

pnpm/action-setup commit 41ff72655975bd51cab0327fa583b6e92b6d3061 v4.2.0

💡 Result:

41ff72655975bd51cab0327fa583b6e92b6d3061 is the commit that pnpm/action-setup tags as v4.2.0. In that release, the main change is “feat: support installation from custom NPM registry (#179)”—it copies an existing workspace .npmrc so pnpm respects custom registry settings when the action self-installs pnpm. (Commit timestamp shown: 2025-10-08.) [1]

You’ll often see this version pinned in workflows as pnpm/action-setup v4.2.0@41ff726... (tag + SHA) for supply-chain safety. [2]


Add explicit cache configuration for pnpm with actions/setup-node@v6.

actions/setup-node@v6 removed automatic pnpm caching—it now only caches npm by default. Add cache: pnpm to the Setup Node.js step to preserve dependency caching performance:

Example fix for resolve-version job (line 82-84)
      - name: Setup Node.js
        uses: actions/setup-node@v6
        with:
          node-version: lts/*
          cache: pnpm

Apply the same change to the create-comfyui-pr job (line 171-176 region). The v6 tags and pnpm commit hash are correct and supported.

🤖 Prompt for AI Agents
In @.github/workflows/release-biweekly-comfyui.yaml around lines 63 - 84, The
Setup Node.js steps using actions/setup-node@v6 are missing explicit pnpm
caching; update the Setup Node.js `with:` blocks (the steps named "Setup
Node.js" in the resolve-version job and the create-comfyui-pr job) to include
`cache: pnpm` alongside the existing `node-version` key so pnpm dependencies are
cached by the action.

Comment thread .github/workflows/release-draft-create.yaml Outdated
snomiao
snomiao previously approved these changes Jan 29, 2026
@DrJKL DrJKL changed the title WIP/Chore: Actions updates and cleanup Chore: Actions updates and cleanup Jan 29, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/weekly-docs-check.yaml (1)

41-49: Avoid redundant global installs by checking global scope.

pnpm list without -g won’t detect globally installed tools, so this will always reinstall on a fresh runner. Consider checking the global scope to skip unnecessary installs.

Proposed tweak
-          if ! pnpm list typescript `@vue/compiler-sfc` >/dev/null 2>&1; then
+          if ! pnpm list -g typescript `@vue/compiler-sfc` >/dev/null 2>&1; then
             echo "Installing TypeScript and Vue compiler globally..."
             pnpm install -g typescript `@vue/compiler-sfc`
           else
             echo "TypeScript and Vue compiler already available locally"
           fi
🤖 Fix all issues with AI agents
In @.github/workflows/pr-claude-review.yaml:
- Line 26: The workflow uses mixed pinning strategies (actions/checkout@v6 and
actions/setup-node@v6 versus SHA-pinned pnpm/action-setup and
anthropics/claude-code-action); pick a consistent approach and apply it across
the referenced actions: either replace the floating tags actions/checkout@v6 and
actions/setup-node@v6 with their corresponding commit SHAs to SHA-pin them
(matching the style used for pnpm/action-setup and
anthropics/claude-code-action) or document the intentional policy for using
floating first-party tags in the repo README; update the workflow entries for
actions/checkout and actions/setup-node (and any other occurrences called out)
to follow the chosen strategy.

In @.github/workflows/release-draft-create.yaml:
- Around line 23-26: The pinned SHAs for two GitHub Actions are incorrect;
update the "uses" entries to reference the correct commits for the intended
versions: replace the pnpm/action-setup SHA with
9fd676a19091d4595eefd76e4bd31c97133911f1 (to match v4.2.0) in the
pnpm/action-setup usage, and replace the pypa/gh-action-pypi-publish SHA with
106e0b0b7c337fa67ed433972f777c6357f78598 (to match v1.13.0) in the
pypa/gh-action-pypi-publish usage so the workflow runs the expected releases.

steps:
- name: Checkout repository
uses: actions/checkout@v5
uses: actions/checkout@v6

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick | 🔵 Trivial

Consider consistent pinning strategy across all actions.

Currently, actions/checkout and actions/setup-node use floating version tags (v6), while pnpm/action-setup and anthropics/claude-code-action are pinned to specific commit SHAs. For maximum security, consider SHA-pinning all actions consistently—floating tags can be moved by maintainers.

If the team intentionally uses floating tags for first-party GitHub actions (for automatic security patches) while pinning third-party actions, that's a valid strategy—just ensure it's documented.

Also applies to: 32-32, 37-37, 47-47

🤖 Prompt for AI Agents
In @.github/workflows/pr-claude-review.yaml at line 26, The workflow uses mixed
pinning strategies (actions/checkout@v6 and actions/setup-node@v6 versus
SHA-pinned pnpm/action-setup and anthropics/claude-code-action); pick a
consistent approach and apply it across the referenced actions: either replace
the floating tags actions/checkout@v6 and actions/setup-node@v6 with their
corresponding commit SHAs to SHA-pin them (matching the style used for
pnpm/action-setup and anthropics/claude-code-action) or document the intentional
policy for using floating first-party tags in the repo README; update the
workflow entries for actions/checkout and actions/setup-node (and any other
occurrences called out) to follow the chosen strategy.

Comment on lines 23 to 26
- name: Install pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
with:
version: 10

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

# First, locate and read the workflow file
cat -n .github/workflows/release-draft-create.yaml

Repository: Comfy-Org/ComfyUI_frontend

Length of output: 6021


🏁 Script executed:

#!/bin/bash
# Verify tag->commit mapping for pinned actions via GitHub API
set -euo pipefail

echo "=== Verifying pnpm/action-setup ==="
# Try to get the commit for v4.2.0 tag
curl -s "https://api.github.com/repos/pnpm/action-setup/git/refs/tags/v4.2.0" | python3 -c "import sys, json; data = json.load(sys.stdin); print('v4.2.0 ref:', data.get('object', {}).get('sha', 'N/A'))" 2>/dev/null || echo "Could not fetch pnpm/action-setup tag"

echo ""
echo "=== Verifying softprops/action-gh-release ==="
curl -s "https://api.github.com/repos/softprops/action-gh-release/git/refs/tags/v2.5.0" | python3 -c "import sys, json; data = json.load(sys.stdin); print('v2.5.0 ref:', data.get('object', {}).get('sha', 'N/A'))" 2>/dev/null || echo "Could not fetch softprops/action-gh-release tag"

echo ""
echo "=== Verifying pypa/gh-action-pypi-publish ==="
curl -s "https://api.github.com/repos/pypa/gh-action-pypi-publish/git/refs/tags/v1.13.0" | python3 -c "import sys, json; data = json.load(sys.stdin); print('v1.13.0 ref:', data.get('object', {}).get('sha', 'N/A'))" 2>/dev/null || echo "Could not fetch pypa/gh-action-pypi-publish tag"

Repository: Comfy-Org/ComfyUI_frontend

Length of output: 359


Fix pinned SHAs: two actions reference incorrect commits.

The SHA verification reveals mismatches:

  • pnpm/action-setup: Pinned SHA 41ff72655975bd51cab0327fa583b6e92b6d3061 does not match v4.2.0's actual commit 9fd676a19091d4595eefd76e4bd31c97133911f1
  • softprops/action-gh-release: Pinned SHA a06a81a03ee405af7f2048a818ed3f03bbf83c7b correctly matches v2.5.0 ✓
  • pypa/gh-action-pypi-publish: Pinned SHA ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e does not match v1.13.0's actual commit 106e0b0b7c337fa67ed433972f777c6357f78598

Update lines 24 and 119 to use the correct SHAs to ensure the intended versions are executed.

🤖 Prompt for AI Agents
In @.github/workflows/release-draft-create.yaml around lines 23 - 26, The pinned
SHAs for two GitHub Actions are incorrect; update the "uses" entries to
reference the correct commits for the intended versions: replace the
pnpm/action-setup SHA with 9fd676a19091d4595eefd76e4bd31c97133911f1 (to match
v4.2.0) in the pnpm/action-setup usage, and replace the
pypa/gh-action-pypi-publish SHA with 106e0b0b7c337fa67ed433972f777c6357f78598
(to match v1.13.0) in the pypa/gh-action-pypi-publish usage so the workflow runs
the expected releases.

@AustinMroz AustinMroz left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are lines here that change things.

Changes seem healthy and I can always hit the revert button if stuff breaks.

@AustinMroz
AustinMroz merged commit bd4920f into main Jan 29, 2026
29 checks passed
@AustinMroz
AustinMroz deleted the drjkl/ci-actions-update branch January 29, 2026 05:22
AustinMroz pushed a commit that referenced this pull request Jan 29, 2026
## Summary

Fixes the snapshot merge failure introduced by PR #8377
(actions/download-artifact v4→v7 upgrade).

## Root Cause

The v5+ release of `download-artifact` changed behavior: when a
`pattern` matches only a **single artifact**, files are extracted
directly to `path/` without the artifact name subdirectory. When only
one shard had changes, the merge loop couldn't find the expected
`snapshots-shard-*/` directories.

## Fix

Use `merge-multiple: true` — the documented pattern for combining
sharded artifacts. This merges all matched artifacts directly into the
target path, eliminating directory structure assumptions.

## Testing

This fix can be validated by re-running the workflow on [PR
#8276](#8276) after
merge.

---
- Fixes snapshot update workflow regression from #8377

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8432-fix-use-merge-multiple-for-snapshot-artifact-download-2f76d73d3650810b97fdfe28cd3c7694)
by [Unito](https://www.unito.io)

Co-authored-by: Subagent 5 <subagent@example.com>
Co-authored-by: Amp <amp@ampcode.com>
christian-byrne pushed a commit that referenced this pull request Jan 30, 2026
## Summary

...

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8377-WIP-Chore-Actions-updates-and-cleanup-2f66d73d3650818483a8dffa32a6f245)
by [Unito](https://www.unito.io)

---------

Co-authored-by: Amp <amp@ampcode.com>
christian-byrne added a commit that referenced this pull request Jan 30, 2026
## Summary

Fixes the snapshot merge failure introduced by PR #8377
(actions/download-artifact v4→v7 upgrade).

## Root Cause

The v5+ release of `download-artifact` changed behavior: when a
`pattern` matches only a **single artifact**, files are extracted
directly to `path/` without the artifact name subdirectory. When only
one shard had changes, the merge loop couldn't find the expected
`snapshots-shard-*/` directories.

## Fix

Use `merge-multiple: true` — the documented pattern for combining
sharded artifacts. This merges all matched artifacts directly into the
target path, eliminating directory structure assumptions.

## Testing

This fix can be validated by re-running the workflow on [PR
#8276](#8276) after
merge.

---
- Fixes snapshot update workflow regression from #8377

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8432-fix-use-merge-multiple-for-snapshot-artifact-download-2f76d73d3650810b97fdfe28cd3c7694)
by [Unito](https://www.unito.io)

Co-authored-by: Subagent 5 <subagent@example.com>
Co-authored-by: Amp <amp@ampcode.com>
DrJKL pushed a commit that referenced this pull request Jan 31, 2026
## Summary

Fixes the snapshot merge failure introduced by PR #8377
(actions/download-artifact v4→v7 upgrade).

## Root Cause

The v5+ release of `download-artifact` changed behavior: when a
`pattern` matches only a **single artifact**, files are extracted
directly to `path/` without the artifact name subdirectory. When only
one shard had changes, the merge loop couldn't find the expected
`snapshots-shard-*/` directories.

## Fix

Use `merge-multiple: true` — the documented pattern for combining
sharded artifacts. This merges all matched artifacts directly into the
target path, eliminating directory structure assumptions.

## Testing

This fix can be validated by re-running the workflow on [PR
#8276](#8276) after
merge.

---
- Fixes snapshot update workflow regression from #8377

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8432-fix-use-merge-multiple-for-snapshot-artifact-download-2f76d73d3650810b97fdfe28cd3c7694)
by [Unito](https://www.unito.io)

Co-authored-by: Subagent 5 <subagent@example.com>
Co-authored-by: Amp <amp@ampcode.com>
christian-byrne added a commit that referenced this pull request Mar 13, 2026
Two issues caused the lint/format CI to be broken for fork PRs:

1. The setup-frontend shared action (created in #8377) was missed when
   Node version was standardized to .nvmrc in #9521. It still used
   node-version: 'lts/*' instead of node-version-file: '.nvmrc',
   causing a version mismatch with the rest of the repo.

2. Fork PRs with auto-fixable lint/format issues silently passed CI.
   The auto-fix steps would fix issues in the workspace, then Final
   validation would pass on the fixed workspace, but the commit step
   was correctly skipped for forks. The 'Comment on PR' step that was
   supposed to tell fork contributors to fix manually used
   continue-on-error: true with actions/github-script — but fork PRs
   have a read-only GITHUB_TOKEN that can't post comments, so it
   silently failed. The net result: fork PRs with lint issues got a
   green checkmark.

Fix: Replace the silent comment step with an explicit failure step
that exits with code 1 and prints clear instructions in the CI log.
Remove the broken fork comment step entirely.
christian-byrne added a commit that referenced this pull request Mar 13, 2026
## Problem

The lint/format CI workflow was broken for fork PRs in two ways:

### 1. Node version mismatch in setup-frontend action
The `setup-frontend` shared action (created in #8377) was missed when
Node version was standardized to `.nvmrc` in #9521. It still used
`node-version: 'lts/*'` instead of `node-version-file: '.nvmrc'`.

### 2. Fork PRs with lint issues silently passed CI
Fork PRs with auto-fixable lint/format issues got a **green checkmark**
despite having unfixed issues:
1. Auto-fix steps (`lint:fix`, `format`) fix issues in the workspace
2. `Commit changes` is correctly skipped for forks (can't push to fork
branches)
3. `Final validation` passes because it runs on the already-fixed
workspace
4. The `Comment on PR about manual fix needed` step tries to post a
comment via `actions/github-script`, but fork PRs have a read-only
`GITHUB_TOKEN` — the comment silently fails (`continue-on-error: true`)
5. **Result**: workflow reports success, contributor thinks their code
is clean

## Fix

- **setup-frontend**: Use `node-version-file: '.nvmrc'` instead of
`node-version: 'lts/*'`
- **ci-lint-format**: Replace the broken fork comment step with an
explicit `exit 1` that fails CI and prints clear fix instructions in the
log. This follows the principle from `.github/AGENTS.md`: fork PRs can't
post comments, so don't try.

## Testing
- [ ] Verify fork PRs with clean code still pass
- [ ] Verify fork PRs with lint issues now properly fail (instead of
silently passing)

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-9846-fix-restore-fork-PR-lint-format-CI-workflow-3226d73d3650811cb5bfe9f1f989cc0c)
by [Unito](https://www.unito.io)
zeekay pushed a commit to hanzoui/frontend that referenced this pull request Jul 26, 2026
## Summary

...

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8377-WIP-Chore-Actions-updates-and-cleanup-2f66d73d3650818483a8dffa32a6f245)
by [Unito](https://www.unito.io)

---------

Co-authored-by: Amp <amp@ampcode.com>
zeekay pushed a commit to hanzoui/frontend that referenced this pull request Jul 26, 2026
## Summary

Fixes the snapshot merge failure introduced by PR Comfy-Org#8377
(actions/download-artifact v4→v7 upgrade).

## Root Cause

The v5+ release of `download-artifact` changed behavior: when a
`pattern` matches only a **single artifact**, files are extracted
directly to `path/` without the artifact name subdirectory. When only
one shard had changes, the merge loop couldn't find the expected
`snapshots-shard-*/` directories.

## Fix

Use `merge-multiple: true` — the documented pattern for combining
sharded artifacts. This merges all matched artifacts directly into the
target path, eliminating directory structure assumptions.

## Testing

This fix can be validated by re-running the workflow on [PR
Comfy-Org#8276](Comfy-Org#8276) after
merge.

---
- Fixes snapshot update workflow regression from Comfy-Org#8377

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8432-fix-use-merge-multiple-for-snapshot-artifact-download-2f76d73d3650810b97fdfe28cd3c7694)
by [Unito](https://www.unito.io)

Co-authored-by: Subagent 5 <subagent@example.com>
Co-authored-by: Amp <amp@ampcode.com>
zeekay pushed a commit to hanzoui/frontend that referenced this pull request Jul 26, 2026
## Summary

...

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8377-WIP-Chore-Actions-updates-and-cleanup-2f66d73d3650818483a8dffa32a6f245)
by [Unito](https://www.unito.io)

---------

Co-authored-by: Amp <amp@ampcode.com>
zeekay pushed a commit to hanzoui/frontend that referenced this pull request Jul 26, 2026
## Summary

Fixes the snapshot merge failure introduced by PR Comfy-Org#8377
(actions/download-artifact v4→v7 upgrade).

## Root Cause

The v5+ release of `download-artifact` changed behavior: when a
`pattern` matches only a **single artifact**, files are extracted
directly to `path/` without the artifact name subdirectory. When only
one shard had changes, the merge loop couldn't find the expected
`snapshots-shard-*/` directories.

## Fix

Use `merge-multiple: true` — the documented pattern for combining
sharded artifacts. This merges all matched artifacts directly into the
target path, eliminating directory structure assumptions.

## Testing

This fix can be validated by re-running the workflow on [PR
Comfy-Org#8276](Comfy-Org#8276) after
merge.

---
- Fixes snapshot update workflow regression from Comfy-Org#8377

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8432-fix-use-merge-multiple-for-snapshot-artifact-download-2f76d73d3650810b97fdfe28cd3c7694)
by [Unito](https://www.unito.io)

Co-authored-by: Subagent 5 <subagent@example.com>
Co-authored-by: Amp <amp@ampcode.com>
dante01yoon pushed a commit that referenced this pull request Jul 27, 2026
## Summary

...

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8377-WIP-Chore-Actions-updates-and-cleanup-2f66d73d3650818483a8dffa32a6f245)
by [Unito](https://www.unito.io)

---------

Co-authored-by: Amp <amp@ampcode.com>
dante01yoon pushed a commit that referenced this pull request Jul 27, 2026
## Summary

Fixes the snapshot merge failure introduced by PR #8377
(actions/download-artifact v4→v7 upgrade).

## Root Cause

The v5+ release of `download-artifact` changed behavior: when a
`pattern` matches only a **single artifact**, files are extracted
directly to `path/` without the artifact name subdirectory. When only
one shard had changes, the merge loop couldn't find the expected
`snapshots-shard-*/` directories.

## Fix

Use `merge-multiple: true` — the documented pattern for combining
sharded artifacts. This merges all matched artifacts directly into the
target path, eliminating directory structure assumptions.

## Testing

This fix can be validated by re-running the workflow on [PR
#8276](#8276) after
merge.

---
- Fixes snapshot update workflow regression from #8377

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-8432-fix-use-merge-multiple-for-snapshot-artifact-download-2f76d73d3650810b97fdfe28cd3c7694)
by [Unito](https://www.unito.io)

Co-authored-by: Subagent 5 <subagent@example.com>
Co-authored-by: Amp <amp@ampcode.com>
dante01yoon pushed a commit that referenced this pull request Jul 27, 2026
## Problem

The lint/format CI workflow was broken for fork PRs in two ways:

### 1. Node version mismatch in setup-frontend action
The `setup-frontend` shared action (created in #8377) was missed when
Node version was standardized to `.nvmrc` in #9521. It still used
`node-version: 'lts/*'` instead of `node-version-file: '.nvmrc'`.

### 2. Fork PRs with lint issues silently passed CI
Fork PRs with auto-fixable lint/format issues got a **green checkmark**
despite having unfixed issues:
1. Auto-fix steps (`lint:fix`, `format`) fix issues in the workspace
2. `Commit changes` is correctly skipped for forks (can't push to fork
branches)
3. `Final validation` passes because it runs on the already-fixed
workspace
4. The `Comment on PR about manual fix needed` step tries to post a
comment via `actions/github-script`, but fork PRs have a read-only
`GITHUB_TOKEN` — the comment silently fails (`continue-on-error: true`)
5. **Result**: workflow reports success, contributor thinks their code
is clean

## Fix

- **setup-frontend**: Use `node-version-file: '.nvmrc'` instead of
`node-version: 'lts/*'`
- **ci-lint-format**: Replace the broken fork comment step with an
explicit `exit 1` that fails CI and prints clear fix instructions in the
log. This follows the principle from `.github/AGENTS.md`: fork PRs can't
post comments, so don't try.

## Testing
- [ ] Verify fork PRs with clean code still pass
- [ ] Verify fork PRs with lint issues now properly fail (instead of
silently passing)

┆Issue is synchronized with this [Notion
page](https://www.notion.so/PR-9846-fix-restore-fork-PR-lint-format-CI-workflow-3226d73d3650811cb5bfe9f1f989cc0c)
by [Unito](https://www.unito.io)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L This PR changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants