Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
96 commits
Select commit Hold shift + click to select a range
880a9e7
pets
flo-bit Jun 16, 2026
fd213fe
add fox
flo-bit Jun 16, 2026
495d1fe
Restore ALT badges in quoted posts (#10964)
jcsalterego Jun 22, 2026
cc0e1f8
Nightly source-language update
pfrazee Jun 23, 2026
c753c94
Process videos on web with WebCodecs (#10955)
vineyardbovines Jun 23, 2026
692d8e5
bskyweb: add isPartOf jsonld post attr (#10945)
blackmichael Jun 23, 2026
ea0ef23
Nightly source-language update
pfrazee Jun 24, 2026
4308d75
Add TestFlight group selection to iOS build workflow (#10979)
vineyardbovines Jun 24, 2026
e371d1d
Add mark all as read to chat settings (#10973)
ds-boyce Jun 24, 2026
c3626c8
Fix embeds overlapping each other in chat (#10949)
ds-boyce Jun 24, 2026
cd4d62c
Remove old message composer (#10951)
ds-boyce Jun 24, 2026
0674626
Add light haptics to Edit Profile Button for labellers (#10948)
RetroSunstar Jun 24, 2026
2843374
Fix setState-in-render warning from convo cache subscription (#10934)
mozzius Jun 24, 2026
f3978d1
Fix internal repo sync broken by actions/checkout v6 bump (#10933)
mozzius Jun 24, 2026
90c010e
Tweak strings and context (#10928)
surfdude29 Jun 24, 2026
5b66015
Set a min height on native Menus (#10956)
ds-boyce Jun 24, 2026
c909fef
signup: align "Contact support" to the right on larger displays (#10978)
iLynxcat Jun 24, 2026
f64b125
[APP-2429] Add Sunlight and Twilight color options to the Invite Frie…
vineyardbovines Jun 24, 2026
da1f637
Fix issue with stale unread message counts (#10953)
ds-boyce Jun 24, 2026
51e2543
Focus composer input when editable (#10982)
ds-boyce Jun 24, 2026
f72aae3
Nightly source-language update
pfrazee Jun 25, 2026
1ff27bf
Upgrade pnpm to 11.9.0 (#10952)
ds-boyce Jun 25, 2026
3b2e609
Add new chat notification preferences (#10972)
ds-boyce Jun 25, 2026
46f5437
Display more information in chat replies (#10950)
ds-boyce Jun 25, 2026
b1b0ad0
Video alt text (#10990)
estrattonbailey Jun 25, 2026
c33a358
Show shorter text for account label badge (#10983)
abenzer Jun 25, 2026
29a0d16
Add icon to AppLanguageDropdown (#10977)
iLynxcat Jun 25, 2026
eae15ac
Increase unread cap to 99+ (#10985)
ds-boyce Jun 25, 2026
6b342f6
Hide autocomplete suggestions when input loses focus (#10989)
ds-boyce Jun 25, 2026
fcf17a4
Add video upload telemetry events (#10991)
vineyardbovines Jun 25, 2026
3086937
Add placeholder, empty-value, and onConfirm support to DateField (#10…
estrattonbailey Jun 25, 2026
ea35d93
Change dialog label and header from 'Invite Friends' to 'Share Profil…
gabecodez Jun 25, 2026
717406f
Nightly source-language update
pfrazee Jun 26, 2026
fcbd23e
Bump actions/download-artifact from 7.0.0 to 8.0.1 (#10971)
dependabot[bot] Jun 26, 2026
66250e4
Clean up type/lint errors in `modules` (#10996)
mozzius Jun 26, 2026
1756740
Add app language: Czech (`cs`) (#10994)
surfdude29 Jun 26, 2026
c5b3810
Fail video duration check before compression (#10999)
vineyardbovines Jun 26, 2026
248290e
Add advanced search UI (#10992)
ds-boyce Jun 26, 2026
90f3f95
Fix GrowthBook exposure did mis-attribution across account switches (…
estrattonbailey Jun 27, 2026
e0ddd8d
Nightly source-language update
pfrazee Jun 27, 2026
b8608ac
Fix 149/150 user limit for starter packs (#11001)
RetroSunstar Jun 28, 2026
257a11d
Set apple team id via environment variable (#11008)
mozzius Jun 29, 2026
a5ed41f
Fix CI - grant workflows permission for internal sync push (#11010)
mozzius Jun 29, 2026
69058e1
Disable selectable profile description on Android (#11002)
mozzius Jun 29, 2026
2971c35
Fix chat input positioning on mobile android (#11013)
mozzius Jun 29, 2026
bd2849d
Release Prep 1.126.0 (#11015)
estrattonbailey Jun 29, 2026
75e2c40
Use correct param name for setup-bundletool action (#11020)
ds-boyce Jun 30, 2026
43d2f93
WSOD when trying to create account from starter pack on non-default p…
c960657 Jun 30, 2026
95726c6
Replace react-native-compressor video path with native expo-bluesky-v…
vineyardbovines Jun 30, 2026
bb20f23
Always scroll to bottom of chat after sending a message (#10913)
ds-boyce Jun 30, 2026
ade5d2b
Cull unused files (#11029)
mozzius Jun 30, 2026
6607118
Remove `react-native-dotenv` (#10706)
mozzius Jun 30, 2026
298c83b
Update search input with `useAutocomplete` (#11023)
ds-boyce Jun 30, 2026
cc89302
Always set `allTime` to `true` for search v2 (#11033)
ds-boyce Jun 30, 2026
28c44a1
Avoid leaking previous messages via replies (#11017)
ds-boyce Jun 30, 2026
44f6a98
Use latest fingerprint-native action (#11016)
ds-boyce Jun 30, 2026
eb755bc
Bump the actions group with 3 updates (#11021)
dependabot[bot] Jun 30, 2026
de51ceb
Bump actions/checkout from 6.0.3 to 7.0.0 (#11022)
dependabot[bot] Jun 30, 2026
52aaba4
Route iOS notification settings intent into the app (#11003)
mozzius Jun 30, 2026
5331c68
Rename root file from `js` to `ts`, improve platform splitting (#11012)
mozzius Jun 30, 2026
8a6a903
Remove actions-up script in favor of Dependabot (#11034)
estrattonbailey Jun 30, 2026
feaca04
Fix UI overlap issue where text was rendering over icons (#10774)
ashish-khankari Jun 30, 2026
57dc53f
Add "fingerprint changed" label to PRs with native changes (#10742)
mozzius Jun 30, 2026
281f499
adding focus to the editing block (#10593)
Zaven477 Jun 30, 2026
9df4add
Only request notification permission once per session (#11004)
mozzius Jun 30, 2026
2516059
Fix hashtag author filter failing for DIDs (#10772)
surfdude29 Jun 30, 2026
22391bc
Fix lint (#11038)
estrattonbailey Jun 30, 2026
f648977
Added Automation label to labeller display names (#11027)
RetroSunstar Jun 30, 2026
13ee5df
Restore link in Go Live prompt if status record present (#10636)
LooneyH Jun 30, 2026
0526820
Fix stale display names for lists/feeds in top bar across restarts/de…
RetroSunstar Jun 30, 2026
5e7343b
Fix yaml syntax in pull-request-commit.yml (#11037)
ds-boyce Jun 30, 2026
0adf500
Use RNKC for composer keyboard avoiding view (#10997)
mozzius Jun 30, 2026
133476e
Update advanced search suggestions (#11036)
ds-boyce Jun 30, 2026
e860679
Nightly source-language update
pfrazee Jul 1, 2026
c4ce3ce
Reduce Sentry noise from logger transport and expected-failure call s…
vineyardbovines Jul 1, 2026
b27ef2b
Bump app version to 1.127.0 (#11040)
estrattonbailey Jul 1, 2026
40df0d7
Fix blank message list after submit on Android (#11042)
ds-boyce Jul 2, 2026
b0a4014
Special-case 'me' values in search queries (#11043)
ds-boyce Jul 2, 2026
954268a
[AAv2] Integrate on-device APIs (#9564)
estrattonbailey Jul 2, 2026
8613bb1
Remove potentially intent violating chat settings restriction (#11056)
estrattonbailey Jul 2, 2026
2eddbf8
Fix back button behavior on login/create account screen (#11052)
ds-boyce Jul 2, 2026
79a1609
Nightly source-language update
pfrazee Jul 3, 2026
5b648cd
fix: show onboarding after OAuth signup without a reload
seboslaw Jul 3, 2026
802cd7a
load OP self-threads past the server depth cap
abcbrookie Jul 4, 2026
999a018
add (x/n) position chips to self-threads
abcbrookie Jul 4, 2026
7ab2c9c
feat: add plyr.fm embed support
zzstoatzz Jun 20, 2026
4e21f39
Merge pull request #133 from eurosky-social/brooke/thread-reader-fixes
flo-bit Jul 6, 2026
37aeaa7
Merge remote-tracking branch 'origin/main' into flo/sync-upstream-202…
flo-bit Jul 6, 2026
ebe0780
Merge pull request #134 from eurosky-social/flo/sync-upstream-2026-07-06
flo-bit Jul 6, 2026
519777a
Merge pull request #120 from zzstoatzz/feat/plyr-fm-embed
flo-bit Jul 6, 2026
317ac81
fix staging build
flo-bit Jul 6, 2026
e8ccffd
Merge pull request #136 from eurosky-social/fix/onboarding
flo-bit Jul 8, 2026
80ff24a
feat(onboarding): seed the fu feed by liking interest posts
seboslaw Jul 8, 2026
62d24d4
Merge remote-tracking branch 'origin/eurosky/fork' into flo/pets
flo-bit Jul 9, 2026
6db6e97
add dogs
flo-bit Jul 9, 2026
296c338
Merge pull request #142 from eurosky-social/flo/pets
flo-bit Jul 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .github/workflows/build-and-push-bskyweb-aws.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Setup Docker buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-and-push-bskyweb-ghcr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Setup Docker buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-and-push-embedr-aws.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Setup Docker buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-and-push-link-aws.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Setup Docker buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-and-push-ogcard-aws.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Setup Docker buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/build-submit-android.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@
fi

- name: ⬇️ Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 5

Expand Down Expand Up @@ -136,7 +136,7 @@
- name: 🔧 Setup bundletool
uses: amyu/setup-bundletool@cc2e1857284660bd625e43f2c8a45626f034302f # v1.1
with:
bundletool-version: "1.17.2"
version: "1.18.3"

- name: 🔑 Decode keystore
run: echo "${{ secrets.ANDROID_KEYSTORE_BASE64 }}" | base64 --decode >
Expand Down Expand Up @@ -227,7 +227,7 @@

- name: ⬇️ Download APK artifact
if: ${{ steps.release-check.outputs.exists == 'true' }}
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ needs.build.outputs.apk-artifact-name }}

Expand All @@ -238,7 +238,7 @@
- name: 📎 Attach APK to GitHub Release
id: attach
if: ${{ steps.release-check.outputs.exists == 'true' }}
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v3.0.1

Check notice on line 241 in .github/workflows/build-submit-android.yml

View workflow job for this annotation

GitHub Actions / Audit workflows with zizmor

superfluous-actions

build-submit-android.yml:241: action functionality is already included by the runner: use `gh release` in a script step
with:
tag_name: ${{ github.ref_name }}
files: Bluesky-${{ needs.build.outputs.package-version }}.apk
Expand Down
27 changes: 16 additions & 11 deletions .github/workflows/build-submit-ios.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,20 +10,24 @@ on:
options:
- testflight
- production
assignTestFlightGroup:
type: boolean
description: Assign the build to the "QA Team" TestFlight group after submitting
default: false
testFlightGroup:
type: choice
description: TestFlight group to assign the build to after submitting
options:
- none
- QA Team
- Software Mansion
default: none
workflow_call:
inputs:
profile:
type: string
description: Build profile to use
required: true
assignTestFlightGroup:
type: boolean
description: Assign the build to the "QA Team" TestFlight group after submitting
default: false
testFlightGroup:
type: string
description: TestFlight group to assign the build to after submitting ("none" to skip)
default: none
outputs:
package-version:
description: Version from package.json
Expand Down Expand Up @@ -56,7 +60,7 @@ jobs:
fi

- name: ⬇️ Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 5

Expand Down Expand Up @@ -212,8 +216,9 @@ jobs:
# TestFlight group. fastlane's distribute_only mode skips the upload and assigns the
# already-submitted build to the group, polling until Apple finishes processing it.
- name: 🧪 Assign build to TestFlight group
if: ${{ inputs.assignTestFlightGroup }}
if: ${{ inputs.testFlightGroup != 'none' }}
env:
TESTFLIGHT_GROUP: ${{ inputs.testFlightGroup }}
ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }}
ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }}
ASC_KEY_P8_BASE64: ${{ secrets.ASC_KEY_P8_BASE64 }}
Expand Down Expand Up @@ -241,7 +246,7 @@ jobs:
app_identifier:"xyz.blueskyweb.app" \
app_version:"$APP_VERSION" \
build_number:"$BUILD_NUMBER" \
groups:"QA Team" \
groups:"$TESTFLIGHT_GROUP" \
notify_external_testers:true

- name: 🔔 Notify Slack of Production Build
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/bundle-deploy-eas-update.yml
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@
fi

- name: ⬇️ Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0

Expand All @@ -70,7 +70,7 @@

- name: 📷 Check fingerprint and install dependencies
id: fingerprint
uses: bluesky-social/github-actions/fingerprint-native@ebc6aa6d7466dc1e78b1e832041b7b81f6f95030 # v0.1.0
uses: bluesky-social/github-actions/fingerprint-native@b5556913e4aef3964cfd5936d0add3fc0d809bdb # v0.1.0

Check warning on line 73 in .github/workflows/bundle-deploy-eas-update.yml

View workflow job for this annotation

GitHub Actions / Audit workflows with zizmor

ref-version-mismatch

bundle-deploy-eas-update.yml:73: action's hash pin has mismatched or missing version comment: points to commit ebc6aa6d7466
with:
profile: ${{ inputs.channel || 'testflight' }}
previous-commit-tag: ${{ inputs.runtimeVersion }}
Expand Down Expand Up @@ -174,7 +174,7 @@
fi

- name: ⬇️ Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 5

Expand Down Expand Up @@ -329,7 +329,7 @@
fi

- name: ⬇️ Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 5

Expand Down Expand Up @@ -396,7 +396,7 @@
- name: 🔧 Setup bundletool
uses: amyu/setup-bundletool@cc2e1857284660bd625e43f2c8a45626f034302f # v1.1
with:
bundletool-version: "1.17.2"
version: "1.18.3"

- name: 🔑 Decode keystore
run: echo "${{ secrets.ANDROID_KEYSTORE_BASE64 }}" | base64 --decode >
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/claude-mention.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 1

Expand All @@ -65,7 +65,7 @@ jobs:
aws-region: us-east-2

- name: Claude
uses: anthropics/claude-code-action@9dd8b95a392eb34b6f5fb56cf5a64cb735912d4b # v1.0.150
uses: anthropics/claude-code-action@30544b674398ee15c84819bd87caf8a87e8c7b55 # v1.0.154
with:
use_bedrock: 'true'
additional_permissions: |
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/claude-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 1

Expand All @@ -51,7 +51,7 @@ jobs:
aws-region: us-east-2

- name: Claude review
uses: anthropics/claude-code-action@9dd8b95a392eb34b6f5fb56cf5a64cb735912d4b # v1.0.150
uses: anthropics/claude-code-action@30544b674398ee15c84819bd87caf8a87e8c7b55 # v1.0.154
with:
use_bedrock: 'true'
additional_permissions: |
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/golang-test-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Git Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Set up Go tooling
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
Expand All @@ -36,7 +36,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Git Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Set up Go tooling
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ jobs:
job: [lint, prettier, typecheck]
steps:
- name: Check out Git repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Verify Node version pins match package.json
run: |
set -euo pipefail
Expand Down Expand Up @@ -87,7 +87,7 @@ jobs:
shard: [1, 2, 3, 4]
steps:
- name: Check out Git repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6.0.9
- name: Install node
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/nightly-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@
notes: ${{ steps.notes.outputs.notes }}
steps:
- name: ⬇️ Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0

Expand Down Expand Up @@ -74,10 +74,10 @@
ios:
name: Nightly iOS Build
needs: [prepare]
uses: ./.github/workflows/build-submit-ios.yml

Check warning on line 77 in .github/workflows/nightly-build.yml

View workflow job for this annotation

GitHub Actions / Audit workflows with zizmor

secrets-inherit

nightly-build.yml:77: secrets unconditionally inherited by called workflow: this reusable workflow
with:
profile: testflight
assignTestFlightGroup: true
testFlightGroup: "QA Team"
secrets: inherit

android:
Expand All @@ -88,7 +88,7 @@
# validates the reusable-workflow permission ceiling, so the caller must grant it here.
permissions:
contents: write
uses: ./.github/workflows/build-submit-android.yml

Check warning on line 91 in .github/workflows/nightly-build.yml

View workflow job for this annotation

GitHub Actions / Audit workflows with zizmor

secrets-inherit

nightly-build.yml:91: secrets unconditionally inherited by called workflow: this reusable workflow
with:
profile: testflight-android
secrets: inherit
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/nightly-update-source-languages.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:

steps:
- name: Check out Git repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ssh-key: ${{secrets.GH_ACTION_DEPLOY_KEY}}
- uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6.0.9
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pull-request-comment.yml
Original file line number Diff line number Diff line change
Expand Up @@ -125,7 +125,7 @@ jobs:
fi

- name: ⬇️ Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ steps.pr-info.outputs.head-sha }}

Expand Down
23 changes: 20 additions & 3 deletions .github/workflows/pull-request-commit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
pull-requests: write
steps:
- name: ⬇️ Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0

Expand Down Expand Up @@ -116,7 +116,7 @@
pull-requests: write
steps:
- name: ⬇️ Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 100

Expand All @@ -134,7 +134,8 @@

- name: 📷 Check fingerprint and install dependencies
id: fingerprint
uses: bluesky-social/github-actions/fingerprint-native@ebc6aa6d7466dc1e78b1e832041b7b81f6f95030 # v0.1.0
timeout-minutes: 5
uses: bluesky-social/github-actions/fingerprint-native@b5556913e4aef3964cfd5936d0add3fc0d809bdb # v0.1.0

Check warning on line 138 in .github/workflows/pull-request-commit.yml

View workflow job for this annotation

GitHub Actions / Audit workflows with zizmor

ref-version-mismatch

pull-request-commit.yml:138: action's hash pin has mismatched or missing version comment: points to commit ebc6aa6d7466
with:
profile: pull-request

Expand Down Expand Up @@ -162,3 +163,19 @@
with:
header: fingerprint-diff
delete: true

- name: 🏷️ Label as fingerprint changed
if: ${{ steps.fingerprint.outputs.includes-changes }}
env:
GH_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
gh pr edit "$PR_NUMBER" --add-label "bot: fingerprint changed" || true

- name: 🏷️ Remove fingerprint changed label
if: ${{ !steps.fingerprint.outputs.includes-changes }}
env:
GH_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
gh pr edit "$PR_NUMBER" --remove-label "bot: fingerprint changed" || true
11 changes: 8 additions & 3 deletions .github/workflows/sync-internal.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,12 @@ jobs:
if: github.repository == 'bluesky-social/social-app'
steps:
- name: Checkout public repo
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0
# Don't persist the checkout auth header; the push below authenticates
# with the app token embedded in the remote URL instead
persist-credentials: false
- name: Generate GitHub App Token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
Expand All @@ -25,14 +28,16 @@ jobs:
private-key: ${{ secrets.SYNC_INTERNAL_PK }}
repositories: social-app-internal
# Scope the token down from the app's full installation permissions;
# pushing is the only thing this token is used for
# pushing is the only thing this token is used for. The workflows
# permission is required because the sync includes files under
# .github/workflows/, which GitHub refuses to push without it.
permission-contents: write
permission-workflows: write
- name: Push to internal repo
env:
TOKEN: ${{ steps.app-token.outputs.token }}
run: |
git config user.name "github-actions"
git config user.email "test@users.noreply.github.com"
git config --unset-all http.https://github.com/.extraheader
git remote add internal https://x-access-token:${TOKEN}@github.com/bluesky-social/social-app-internal.git
git push internal main --force
2 changes: 1 addition & 1 deletion .github/workflows/verify-pnpm-lock.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out PR HEAD
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0

Expand Down
Loading
Loading