Skip to content

build: bump the npm group across 1 directory with 126 updates #147

build: bump the npm group across 1 directory with 126 updates

build: bump the npm group across 1 directory with 126 updates #147

Workflow file for this run

---
name: CI
on:
pull_request:
branches:
- main
paths-ignore:
- "**.md"
# Least-privilege default; jobs that need more escalate explicitly.
permissions:
contents: read
# Manage concurrency to stop running jobs and start new ones in case of new commit pushed
concurrency:
group: ${{ github.ref }}-${{ github.workflow }}
cancel-in-progress: true
jobs:
commit-lint:
runs-on: ubuntu-latest
if: ${{ github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- name: Checkout sources
uses: actions/checkout@v7
with:
persist-credentials: false
fetch-depth: 0
- name: Setup node
uses: actions/setup-node@v7
with:
node-version: 'lts/*'
- name: Setup dependencies, cache and install
uses: ./.github/actions/install
- name: Lint commits
uses: wagoid/commitlint-github-action@v6
env:
NODE_PATH: ${{ github.workspace }}/node_modules
continue-on-error: true
pull-request-lint:
runs-on: ubuntu-latest
permissions:
pull-requests: read
steps:
- name: Lint PR
uses: amannn/action-semantic-pull-request@v6
env:
GITHUB_TOKEN: ${{ github.token }}
npm-lint:
runs-on: ubuntu-latest
steps:
- name: Checkout sources
uses: actions/checkout@v7
with:
persist-credentials: false
- name: Setup node
uses: actions/setup-node@v7
with:
node-version: 'lts/*'
- name: Setup dependencies, cache and install
uses: ./.github/actions/install
# Every dependency is pinned exactly, so anything behind latest surfaces
# here. This is the drift control referenced by .npmrc and CONTRIBUTING.
- name: Check outdated dependencies
run: npm outdated
- name: Check unused dependencies
run: npm run lint:dependencies
- name: Check dependencies node engines
run: npm run lint:engine
- name: Audit dependencies
run: npm audit --audit-level=high
megalinter:
runs-on: ubuntu-latest
steps:
# Git Checkout
- name: Checkout Code
uses: actions/checkout@v7
with:
persist-credentials: false
# MegaLinter
- name: MegaLinter
# You can override MegaLinter flavor used to have faster performances
# More info at https://megalinter.io/latest/flavors/
uses: oxsecurity/megalinter/flavors/javascript@v9
env:
# All available variables are described in documentation
# https://megalinter.io/latest/config-file/
APPLY_FIXES: all
VALIDATE_ALL_CODEBASE: true
# ADD CUSTOM ENV VARIABLES HERE TO OVERRIDE VALUES OF .mega-linter.yml AT THE ROOT OF YOUR REPOSITORY
- uses: actions/upload-artifact@v7
if: always()
with:
name: megalinter-reports
path: |
megalinter-reports
mega-linter.log
# Opt-in via the 'mutation-testing' label and non-blocking: the run is
# expensive and its signal is advisory. Scope comes from the diff against
# the base branch, which is why the checkout needs full history.
mutation-testing:
runs-on: ubuntu-latest
continue-on-error: true
if: contains(github.event.pull_request.labels.*.name, 'mutation-testing')
steps:
- name: Checkout sources
uses: actions/checkout@v7
with:
persist-credentials: false
fetch-depth: 0
- name: Setup node
uses: actions/setup-node@v7
with:
node-version: 'lts/*'
- uses: google/wireit@setup-github-actions-caching/v2
- name: Setup dependencies, cache and install
uses: ./.github/actions/install
- name: Run incremental mutation testing
run: npm run test:mutation:incremental
- name: Upload mutation report
uses: actions/upload-artifact@v7
if: always()
with:
name: mutation-report
path: reports/mutation
build:
uses: ./.github/workflows/reusable-build.yml
perf:
needs: [build]
permissions:
contents: write
pull-requests: write
uses: ./.github/workflows/reusable-perf.yml
# Publishes a per-commit preview build and runs the e2e matrix against it.
#
# Gated on build so a red pull request never burns a publish or nine e2e legs.
# No token is passed: the pkg-pr-new CLI identifies the workflow run to its
# GitHub App, which is what lets fork pull requests publish. Two settings live
# outside this file and each changes a security property:
# 1. the pkg.pr.new GitHub App must be installed, or this job 404s;
# 2. fork pull request approval gates who may publish under this package
# name - the GitHub default covers first-time contributors only.
preview:
needs: [build]
if: github.actor != 'dependabot[bot]'
runs-on: ubuntu-latest
permissions:
contents: read
outputs:
channel: ${{ steps.preview.outputs.urls }}
steps:
- name: Checkout sources
uses: actions/checkout@v7
with:
persist-credentials: false
- name: Setup node
uses: actions/setup-node@v7
with:
node-version: 'lts/*'
- name: Setup dependencies, cache and install
uses: ./.github/actions/install
- name: Build plugin
run: npm run build
- name: Publish preview
id: preview
run: npm run preview:publish
# Separate job on purpose: it is the only one holding a write scope, and it
# checks out nothing and runs no repository code. A failed comment must also
# not skip the e2e matrix, which fans out from preview independently.
# Skipped for fork pull requests, whose token is read-only regardless.
comment:
needs: [preview]
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
permissions:
pull-requests: write
steps:
- name: Comment install command
uses: thollander/actions-comment-pull-request@v3
with:
message: |
Preview build for this pull request:
```sh
sf plugins install ${{ needs.preview.outputs.channel }}
```
comment-tag: dev-publish
mode: recreate
e2e-tests:
needs: [preview]
permissions:
contents: read
uses: ./.github/workflows/run-e2e-tests.yml
with:
channel: ${{ needs.preview.outputs.channel }}