|
15 | 15 | runs-on: ubuntu-latest |
16 | 16 | timeout-minutes: 10 |
17 | 17 | steps: |
18 | | - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 |
19 | | - with: |
20 | | - persist-credentials: false |
| 18 | + - name: Checkout source |
| 19 | + shell: bash |
| 20 | + env: |
| 21 | + CHECKOUT_REF: ${{ github.sha }} |
| 22 | + GITHUB_TOKEN: ${{ github.token }} |
| 23 | + SERVER_URL: ${{ github.server_url }} |
| 24 | + REPOSITORY: ${{ github.repository }} |
| 25 | + run: | |
| 26 | + set -euo pipefail |
| 27 | + git init -q |
| 28 | + git config --local advice.detachedHead false |
| 29 | + git remote add origin "${SERVER_URL}/${REPOSITORY}" |
| 30 | + AUTH_B64="$(printf 'x-access-token:%s' "$GITHUB_TOKEN" | base64 | tr -d '\n')" |
| 31 | + export GIT_CONFIG_COUNT=1 |
| 32 | + export GIT_CONFIG_KEY_0="http.${SERVER_URL}/.extraheader" |
| 33 | + export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}" |
| 34 | + git fetch --no-tags --depth=1 origin "$CHECKOUT_REF" |
| 35 | + git checkout -q --detach FETCH_HEAD |
21 | 36 |
|
22 | 37 | - name: Install zizmor |
23 | 38 | shell: bash |
@@ -108,10 +123,11 @@ jobs: |
108 | 123 | fi |
109 | 124 | echo "$PNPM_DIR" >> "${GITHUB_PATH:-/dev/null}" |
110 | 125 |
|
111 | | - - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 |
112 | | - with: |
113 | | - node-version: 25.9.0 |
114 | | - cache: pnpm |
| 126 | + - name: Install Node.js |
| 127 | + shell: bash |
| 128 | + env: |
| 129 | + NODE_VERSION: 25.9.0 |
| 130 | + run: node scripts/ci/setup-node.mjs --version "$NODE_VERSION" |
115 | 131 |
|
116 | 132 | - name: Download sfw |
117 | 133 | shell: bash |
@@ -236,16 +252,33 @@ jobs: |
236 | 252 | run: pnpm install --loglevel error |
237 | 253 |
|
238 | 254 | - name: Lint |
239 | | - run: pnpm check:lint |
| 255 | + run: | |
| 256 | + pnpm run check:actions |
| 257 | + pnpm check:lint |
240 | 258 |
|
241 | 259 | typecheck: |
242 | 260 | name: 🔍 Type Check |
243 | 261 | runs-on: ubuntu-latest |
244 | 262 | timeout-minutes: 10 |
245 | 263 | steps: |
246 | | - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 |
247 | | - with: |
248 | | - persist-credentials: false |
| 264 | + - name: Checkout source |
| 265 | + shell: bash |
| 266 | + env: |
| 267 | + CHECKOUT_REF: ${{ github.sha }} |
| 268 | + GITHUB_TOKEN: ${{ github.token }} |
| 269 | + SERVER_URL: ${{ github.server_url }} |
| 270 | + REPOSITORY: ${{ github.repository }} |
| 271 | + run: | |
| 272 | + set -euo pipefail |
| 273 | + git init -q |
| 274 | + git config --local advice.detachedHead false |
| 275 | + git remote add origin "${SERVER_URL}/${REPOSITORY}" |
| 276 | + AUTH_B64="$(printf 'x-access-token:%s' "$GITHUB_TOKEN" | base64 | tr -d '\n')" |
| 277 | + export GIT_CONFIG_COUNT=1 |
| 278 | + export GIT_CONFIG_KEY_0="http.${SERVER_URL}/.extraheader" |
| 279 | + export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}" |
| 280 | + git fetch --no-tags --depth=1 origin "$CHECKOUT_REF" |
| 281 | + git checkout -q --detach FETCH_HEAD |
249 | 282 |
|
250 | 283 | - name: Install pnpm |
251 | 284 | shell: bash |
@@ -284,10 +317,11 @@ jobs: |
284 | 317 | fi |
285 | 318 | echo "$PNPM_DIR" >> "${GITHUB_PATH:-/dev/null}" |
286 | 319 |
|
287 | | - - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 |
288 | | - with: |
289 | | - node-version: 25.9.0 |
290 | | - cache: pnpm |
| 320 | + - name: Install Node.js |
| 321 | + shell: bash |
| 322 | + env: |
| 323 | + NODE_VERSION: 25.9.0 |
| 324 | + run: node scripts/ci/setup-node.mjs --version "$NODE_VERSION" |
291 | 325 |
|
292 | 326 | - name: Download sfw |
293 | 327 | shell: bash |
@@ -425,9 +459,24 @@ jobs: |
425 | 459 | node-version: [22, 24] |
426 | 460 | os: [ubuntu-latest] |
427 | 461 | steps: |
428 | | - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 |
429 | | - with: |
430 | | - persist-credentials: false |
| 462 | + - name: Checkout source |
| 463 | + shell: bash |
| 464 | + env: |
| 465 | + CHECKOUT_REF: ${{ github.sha }} |
| 466 | + GITHUB_TOKEN: ${{ github.token }} |
| 467 | + SERVER_URL: ${{ github.server_url }} |
| 468 | + REPOSITORY: ${{ github.repository }} |
| 469 | + run: | |
| 470 | + set -euo pipefail |
| 471 | + git init -q |
| 472 | + git config --local advice.detachedHead false |
| 473 | + git remote add origin "${SERVER_URL}/${REPOSITORY}" |
| 474 | + AUTH_B64="$(printf 'x-access-token:%s' "$GITHUB_TOKEN" | base64 | tr -d '\n')" |
| 475 | + export GIT_CONFIG_COUNT=1 |
| 476 | + export GIT_CONFIG_KEY_0="http.${SERVER_URL}/.extraheader" |
| 477 | + export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}" |
| 478 | + git fetch --no-tags --depth=1 origin "$CHECKOUT_REF" |
| 479 | + git checkout -q --detach FETCH_HEAD |
431 | 480 |
|
432 | 481 | - name: Install pnpm |
433 | 482 | shell: bash |
@@ -466,10 +515,11 @@ jobs: |
466 | 515 | fi |
467 | 516 | echo "$PNPM_DIR" >> "${GITHUB_PATH:-/dev/null}" |
468 | 517 |
|
469 | | - - uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 |
470 | | - with: |
471 | | - node-version: ${{ matrix.node-version }} |
472 | | - cache: pnpm |
| 518 | + - name: Install Node.js |
| 519 | + shell: bash |
| 520 | + env: |
| 521 | + NODE_VERSION: ${{ matrix.node-version }} |
| 522 | + run: node scripts/ci/setup-node.mjs --version "$NODE_VERSION" |
473 | 523 |
|
474 | 524 | - name: Download sfw |
475 | 525 | shell: bash |
|
0 commit comments