From 61ed044a2c11d1c359d96df1c2b9e7705752e476 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 24 Jun 2026 16:06:17 +0000 Subject: [PATCH 1/3] chore(deps): bump the actions group across 1 directory with 13 updates Bumps the actions group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4` | `7` | | [actions/github-script](https://github.com/actions/github-script) | `7` | `9` | | [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) | `2` | `3` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4` | `5` | | [actions/setup-go](https://github.com/actions/setup-go) | `5` | `6` | | [actions/labeler](https://github.com/actions/labeler) | `5` | `6` | | [dessant/lock-threads](https://github.com/dessant/lock-threads) | `5` | `6` | | [pnpm/action-setup](https://github.com/pnpm/action-setup) | `4` | `6` | | [actions/setup-node](https://github.com/actions/setup-node) | `4` | `6` | | [actions/setup-python](https://github.com/actions/setup-python) | `5` | `6` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `3` | `7` | | [amannn/action-semantic-pull-request](https://github.com/amannn/action-semantic-pull-request) | `5` | `6` | | [actions/stale](https://github.com/actions/stale) | `9` | `10` | Updates `actions/checkout` from 4 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4...v7) Updates `actions/github-script` from 7 to 9 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v7...v9) Updates `dependabot/fetch-metadata` from 2 to 3 - [Release notes](https://github.com/dependabot/fetch-metadata/releases) - [Commits](https://github.com/dependabot/fetch-metadata/compare/v2...v3) Updates `actions/dependency-review-action` from 4 to 5 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](https://github.com/actions/dependency-review-action/compare/v4...v5) Updates `actions/setup-go` from 5 to 6 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](https://github.com/actions/setup-go/compare/v5...v6) Updates `actions/labeler` from 5 to 6 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](https://github.com/actions/labeler/compare/v5...v6) Updates `dessant/lock-threads` from 5 to 6 - [Release notes](https://github.com/dessant/lock-threads/releases) - [Changelog](https://github.com/dessant/lock-threads/blob/main/CHANGELOG.md) - [Commits](https://github.com/dessant/lock-threads/compare/v5...v6) Updates `pnpm/action-setup` from 4 to 6 - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](https://github.com/pnpm/action-setup/compare/v4...v6) Updates `actions/setup-node` from 4 to 6 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v4...v6) Updates `actions/setup-python` from 5 to 6 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/v5...v6) Updates `astral-sh/setup-uv` from 3 to 7 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](https://github.com/astral-sh/setup-uv/compare/v3...v7) Updates `amannn/action-semantic-pull-request` from 5 to 6 - [Release notes](https://github.com/amannn/action-semantic-pull-request/releases) - [Changelog](https://github.com/amannn/action-semantic-pull-request/blob/main/CHANGELOG.md) - [Commits](https://github.com/amannn/action-semantic-pull-request/compare/v5...v6) Updates `actions/stale` from 9 to 10 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/stale/compare/v9...v10) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/dependency-review-action dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/labeler dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-go dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-node dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-python dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/stale dependency-version: '10' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: amannn/action-semantic-pull-request dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: astral-sh/setup-uv dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: dependabot/fetch-metadata dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: dessant/lock-threads dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: pnpm/action-setup dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/actionlint.yml | 2 +- .github/workflows/anomaly-to-issue.yml | 4 ++-- .github/workflows/anomaly-triage.yml | 6 ++--- .github/workflows/auto-merge-dependabot.yml | 2 +- .github/workflows/branch-naming.yml | 2 +- .github/workflows/changelog-fragment.yml | 2 +- .github/workflows/dependency-review.yml | 4 ++-- .github/workflows/doc-orphan-detector.yml | 4 ++-- .github/workflows/doc-policy-lint.yml | 4 ++-- .github/workflows/go-ci.yml | 4 ++-- .github/workflows/labeler.yml | 2 +- .github/workflows/lock-threads.yml | 2 +- .github/workflows/node-ci.yml | 6 ++--- .github/workflows/pr-body-autoinject.yml | 2 +- .github/workflows/pr-policy.yml | 10 ++++----- .github/workflows/python-ci.yml | 6 ++--- .github/workflows/repo-required-gate.yml | 22 +++++++++---------- .../workflows/repo-update-log-fragment.yml | 4 ++-- .github/workflows/self-test.yml | 4 ++-- .github/workflows/semantic-pr-title.yml | 2 +- .github/workflows/stale.yml | 4 ++-- 21 files changed, 49 insertions(+), 49 deletions(-) diff --git a/.github/workflows/actionlint.yml b/.github/workflows/actionlint.yml index 039db67..b95d637 100644 --- a/.github/workflows/actionlint.yml +++ b/.github/workflows/actionlint.yml @@ -35,7 +35,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Run actionlint uses: raven-actions/actionlint@v2 diff --git a/.github/workflows/anomaly-to-issue.yml b/.github/workflows/anomaly-to-issue.yml index 429ca01..062eec4 100644 --- a/.github/workflows/anomaly-to-issue.yml +++ b/.github/workflows/anomaly-to-issue.yml @@ -40,10 +40,10 @@ jobs: issues: write pull-requests: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: ref: ${{ github.event.pull_request.merge_commit_sha }} - - uses: actions/github-script@v7 + - uses: actions/github-script@v9 env: ANOMALY_DIR: ${{ inputs.anomaly-dir }} README_NAME: ${{ inputs.readme-filename }} diff --git a/.github/workflows/anomaly-triage.yml b/.github/workflows/anomaly-triage.yml index 3107ede..bb2fd44 100644 --- a/.github/workflows/anomaly-triage.yml +++ b/.github/workflows/anomaly-triage.yml @@ -65,13 +65,13 @@ jobs: issues: write steps: - name: Checkout PR head - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: ref: ${{ github.event.pull_request.head.sha }} fetch-depth: 0 - name: Triage anomalies - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: ANOMALIES_PATH: ${{ inputs.anomalies-path }} DEFAULT_DOWNSTREAM: ${{ inputs.default-downstream-repo }} @@ -316,7 +316,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Run actionlint uses: raven-actions/actionlint@v2 with: diff --git a/.github/workflows/auto-merge-dependabot.yml b/.github/workflows/auto-merge-dependabot.yml index 5a70e9b..a7ac068 100644 --- a/.github/workflows/auto-merge-dependabot.yml +++ b/.github/workflows/auto-merge-dependabot.yml @@ -32,7 +32,7 @@ jobs: steps: - name: Fetch Dependabot metadata id: meta - uses: dependabot/fetch-metadata@v2 + uses: dependabot/fetch-metadata@v3 with: github-token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/branch-naming.yml b/.github/workflows/branch-naming.yml index 783254e..c2b09bb 100644 --- a/.github/workflows/branch-naming.yml +++ b/.github/workflows/branch-naming.yml @@ -33,7 +33,7 @@ jobs: permissions: pull-requests: read steps: - - uses: actions/github-script@v7 + - uses: actions/github-script@v9 env: BRANCH_PATTERN: ${{ inputs.pattern }} ENFORCE: ${{ inputs.enforce }} diff --git a/.github/workflows/changelog-fragment.yml b/.github/workflows/changelog-fragment.yml index 626f1d6..1bc6b7c 100644 --- a/.github/workflows/changelog-fragment.yml +++ b/.github/workflows/changelog-fragment.yml @@ -35,7 +35,7 @@ jobs: pull-requests: read contents: read steps: - - uses: actions/github-script@v7 + - uses: actions/github-script@v9 env: SRC_PREFIX: ${{ inputs.src-path-prefix }} FRAGMENT_DIR: ${{ inputs.fragment-dir }} diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index e1b15ce..40211e8 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -35,8 +35,8 @@ jobs: contents: read pull-requests: write steps: - - uses: actions/checkout@v4 - - uses: actions/dependency-review-action@v4 + - uses: actions/checkout@v7 + - uses: actions/dependency-review-action@v5 with: fail-on-severity: ${{ inputs.fail-on-severity }} fail-on-scopes: ${{ inputs.fail-on-scopes }} diff --git a/.github/workflows/doc-orphan-detector.yml b/.github/workflows/doc-orphan-detector.yml index 08d3dbd..365037f 100644 --- a/.github/workflows/doc-orphan-detector.yml +++ b/.github/workflows/doc-orphan-detector.yml @@ -43,13 +43,13 @@ jobs: contents: read issues: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: # Full history + all branches so `origin/main...` diffs and # per-path commit timestamps are available for every branch. fetch-depth: 0 - - uses: actions/github-script@v7 + - uses: actions/github-script@v9 env: STALE_HOURS: ${{ inputs.stale-hours }} BASE_LABEL: ${{ inputs.base-label }} diff --git a/.github/workflows/doc-policy-lint.yml b/.github/workflows/doc-policy-lint.yml index 8ea8884..bc82050 100644 --- a/.github/workflows/doc-policy-lint.yml +++ b/.github/workflows/doc-policy-lint.yml @@ -47,12 +47,12 @@ jobs: contents: read steps: - name: Check out caller repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: fetch-depth: 0 - name: Check out github-workflows for doc-policy helper scripts - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: ArchonVII/github-workflows ref: ${{ inputs.workflow-library-ref }} diff --git a/.github/workflows/go-ci.yml b/.github/workflows/go-ci.yml index f482eb1..483fb3e 100644 --- a/.github/workflows/go-ci.yml +++ b/.github/workflows/go-ci.yml @@ -89,9 +89,9 @@ jobs: os: ${{ fromJSON(inputs.os-matrix) }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - - uses: actions/setup-go@v5 + - uses: actions/setup-go@v6 with: go-version: ${{ matrix.go }} cache: ${{ inputs.cache }} diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml index 3e98472..6a0e9af 100644 --- a/.github/workflows/labeler.yml +++ b/.github/workflows/labeler.yml @@ -24,7 +24,7 @@ jobs: contents: read pull-requests: write steps: - - uses: actions/labeler@v5 + - uses: actions/labeler@v6 with: repo-token: ${{ secrets.GITHUB_TOKEN }} sync-labels: ${{ inputs.sync-labels }} diff --git a/.github/workflows/lock-threads.yml b/.github/workflows/lock-threads.yml index 5e13709..6850df5 100644 --- a/.github/workflows/lock-threads.yml +++ b/.github/workflows/lock-threads.yml @@ -33,7 +33,7 @@ jobs: issues: write pull-requests: write steps: - - uses: dessant/lock-threads@v5 + - uses: dessant/lock-threads@v6 with: issue-inactive-days: ${{ inputs.issue-inactive-days }} pr-inactive-days: ${{ inputs.pr-inactive-days }} diff --git a/.github/workflows/node-ci.yml b/.github/workflows/node-ci.yml index 09536b2..d2d52c5 100644 --- a/.github/workflows/node-ci.yml +++ b/.github/workflows/node-ci.yml @@ -66,7 +66,7 @@ jobs: os: ${{ fromJSON(inputs.os-matrix) }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Detect package manager id: pm @@ -163,12 +163,12 @@ jobs: - name: Set up pnpm if: steps.pm.outputs.manager == 'pnpm' - uses: pnpm/action-setup@v4 + uses: pnpm/action-setup@v6 with: version: ${{ inputs.pnpm-version }} run_install: false - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v6 with: node-version: ${{ matrix.node }} cache: ${{ steps.pm.outputs.cache }} diff --git a/.github/workflows/pr-body-autoinject.yml b/.github/workflows/pr-body-autoinject.yml index 262dd43..295bc47 100644 --- a/.github/workflows/pr-body-autoinject.yml +++ b/.github/workflows/pr-body-autoinject.yml @@ -29,7 +29,7 @@ jobs: pull-requests: write contents: read steps: - - uses: actions/github-script@v7 + - uses: actions/github-script@v9 env: DOC_EXT_LIST: ${{ inputs.doc-only-extensions }} DOC_PREFIXES: ${{ inputs.doc-only-path-prefixes }} diff --git a/.github/workflows/pr-policy.yml b/.github/workflows/pr-policy.yml index 988b8db..66d6e9d 100644 --- a/.github/workflows/pr-policy.yml +++ b/.github/workflows/pr-policy.yml @@ -147,14 +147,14 @@ jobs: # (2026-05-20), finding M1. - name: Check out github-workflows for policy helper scripts if: github.event.pull_request.draft == false - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: ArchonVII/github-workflows ref: ${{ inputs.workflow-library-ref }} path: __github-workflows__ - name: Enforce ready-for-review PR policy - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: REQUIRE_LINKED_ISSUE: ${{ inputs.require-linked-issue }} REQUIRE_VERIFICATION_SECTION: ${{ inputs.require-verification-section }} @@ -246,7 +246,7 @@ jobs: # ---------------------------------------------------------------------- - name: Role separation check if: inputs.role-separation-warnings || inputs.enforce-role-separation - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: ENFORCE_ROLE_SEPARATION: ${{ inputs.enforce-role-separation }} ROLE_PROTECTED_PATHS: ${{ inputs.role-protected-paths }} @@ -360,7 +360,7 @@ jobs: # update. The exemption lives upstream in the commit path. # ---------------------------------------------------------------------- - name: Evidence check (warning-only by default) - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: DOC_EXT_LIST: ${{ inputs.doc-only-extensions }} DOC_PREFIXES: ${{ inputs.doc-only-path-prefixes }} @@ -494,7 +494,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Run actionlint uses: raven-actions/actionlint@v2 with: diff --git a/.github/workflows/python-ci.yml b/.github/workflows/python-ci.yml index 9eda6b6..b309dc8 100644 --- a/.github/workflows/python-ci.yml +++ b/.github/workflows/python-ci.yml @@ -68,15 +68,15 @@ jobs: os: ${{ fromJSON(inputs.os-matrix) }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - - uses: actions/setup-python@v5 + - uses: actions/setup-python@v6 with: python-version: ${{ matrix.python }} - name: Install uv if: inputs.use-uv - uses: astral-sh/setup-uv@v3 + uses: astral-sh/setup-uv@v7 - name: Install dependencies shell: bash diff --git a/.github/workflows/repo-required-gate.yml b/.github/workflows/repo-required-gate.yml index dc1c82d..faa8594 100644 --- a/.github/workflows/repo-required-gate.yml +++ b/.github/workflows/repo-required-gate.yml @@ -239,7 +239,7 @@ jobs: # `workflow-library-ref` (default v1) so parser+workflow are versioned # together. - name: Check out github-workflows for classifier script - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: ArchonVII/github-workflows ref: ${{ inputs.workflow-library-ref }} @@ -247,7 +247,7 @@ jobs: - name: Classify changed files id: detect - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: STACK: ${{ inputs.stack }} NODE_PATHS: ${{ inputs.node-paths }} @@ -370,14 +370,14 @@ jobs: pull-requests: write steps: - name: Check out github-workflows for PR contract validator - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: ArchonVII/github-workflows ref: ${{ inputs.workflow-library-ref }} path: __github-workflows__ - name: Enforce PR policy - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: BRANCH_PATTERN: ${{ inputs.branch-pattern }} REQUIRE_LINKED_ISSUE: ${{ inputs.require-linked-issue }} @@ -505,7 +505,7 @@ jobs: # 2026-06-07 (ArchonVII/hudson-bend#43; #53). - name: Warn if the repo PR template can't pass the contract if: ${{ !cancelled() && github.event.pull_request.draft == false }} - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: WORKFLOW_LIBRARY_REF: ${{ inputs.workflow-library-ref }} with: @@ -572,7 +572,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Run actionlint if: ${{ hashFiles('.github/workflows/*.yml', '.github/workflows/*.yaml') != '' }} uses: raven-actions/actionlint@v2 @@ -603,7 +603,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Validate check map shell: bash run: | @@ -623,9 +623,9 @@ jobs: contents: read pull-requests: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Dependency review - uses: actions/dependency-review-action@v4 + uses: actions/dependency-review-action@v5 with: fail-on-severity: high fail-on-scopes: runtime @@ -690,9 +690,9 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v6 with: node-version: ${{ fromJSON(inputs.node-versions)[0] }} diff --git a/.github/workflows/repo-update-log-fragment.yml b/.github/workflows/repo-update-log-fragment.yml index 54d0a04..42a0042 100644 --- a/.github/workflows/repo-update-log-fragment.yml +++ b/.github/workflows/repo-update-log-fragment.yml @@ -63,14 +63,14 @@ jobs: contents: read steps: - name: Check out github-workflows for ledger validator - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: ArchonVII/github-workflows ref: ${{ inputs.workflow-library-ref }} path: __github-workflows__ - name: Enforce repo update log fragment - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: FRAGMENT_DIR: ${{ inputs.fragment-dir }} WORKFLOW_LIBRARY_REF: ${{ inputs.workflow-library-ref }} diff --git a/.github/workflows/self-test.yml b/.github/workflows/self-test.yml index be75ec8..384fc29 100644 --- a/.github/workflows/self-test.yml +++ b/.github/workflows/self-test.yml @@ -29,9 +29,9 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v6 with: node-version: "20" cache: "npm" diff --git a/.github/workflows/semantic-pr-title.yml b/.github/workflows/semantic-pr-title.yml index dea402a..b429e0a 100644 --- a/.github/workflows/semantic-pr-title.yml +++ b/.github/workflows/semantic-pr-title.yml @@ -49,7 +49,7 @@ jobs: permissions: pull-requests: read steps: - - uses: amannn/action-semantic-pull-request@v5 + - uses: amannn/action-semantic-pull-request@v6 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index d8744a4..094397f 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -1,6 +1,6 @@ name: Stale (reusable) -# Auto-mark and auto-close stale issues and PRs. Wraps actions/stale@v9 so +# Auto-mark and auto-close stale issues and PRs. Wraps actions/stale@v10 so # every consumer repo gets the same versioning and a consistent tone. # # Defaults are conservative: 60 days idle → marked stale, another 14 days @@ -48,7 +48,7 @@ jobs: issues: write pull-requests: write steps: - - uses: actions/stale@v9 + - uses: actions/stale@v10 with: days-before-stale: ${{ inputs.days-before-stale }} days-before-close: ${{ inputs.days-before-close }} From 3c0b3ac73cd1f7cb75e6f81d1ff52a78efe9706e Mon Sep 17 00:00:00 2001 From: Joseph Aguirre <87541003+ArchonVII@users.noreply.github.com> Date: Sat, 27 Jun 2026 15:44:08 -0500 Subject: [PATCH 2/3] test: make node-ci action-version assertions version-agnostic (#68) Future dependabot action bumps no longer break these structure assertions. --- scripts/workflow-structure.test.mjs | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/workflow-structure.test.mjs b/scripts/workflow-structure.test.mjs index ee0d867..aaf2180 100644 --- a/scripts/workflow-structure.test.mjs +++ b/scripts/workflow-structure.test.mjs @@ -24,7 +24,7 @@ describe('node-ci workflow package-manager setup', () => { const detectIndex = body.indexOf('- name: Detect package manager'); const setupPnpmIndex = body.indexOf('- name: Set up pnpm'); - const setupNodeIndex = body.indexOf('- uses: actions/setup-node@v4'); + const setupNodeIndex = body.search(/- uses: actions/setup-node@vd+/); expect(detectIndex).toBeGreaterThan(-1); expect(setupPnpmIndex).toBeGreaterThan(detectIndex); @@ -34,7 +34,7 @@ describe('node-ci workflow package-manager setup', () => { it('installs pnpm before setup-node enables pnpm caching', () => { const body = readWorkflow('node-ci'); - expect(body).toContain('uses: pnpm/action-setup@v4'); + expect(body).toMatch(/uses: pnpm/action-setup@vd+/); expect(body).toContain("if: steps.pm.outputs.manager == 'pnpm'"); expect(body).toContain('version: ${{ inputs.pnpm-version }}'); expect(body).toContain('run_install: false'); From c7a4c6f69b19dee974be21d54633f5fc96afa91a Mon Sep 17 00:00:00 2001 From: Joseph Aguirre <87541003+ArchonVII@users.noreply.github.com> Date: Sat, 27 Jun 2026 15:45:30 -0500 Subject: [PATCH 3/3] test: make node-ci action-version assertions version-agnostic (#68) Use regex (@v\d+) so future dependabot action bumps don't break these structure assertions. Fixes the malformed regex from the prior commit. --- scripts/workflow-structure.test.mjs | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/workflow-structure.test.mjs b/scripts/workflow-structure.test.mjs index aaf2180..7ec391e 100644 --- a/scripts/workflow-structure.test.mjs +++ b/scripts/workflow-structure.test.mjs @@ -24,7 +24,7 @@ describe('node-ci workflow package-manager setup', () => { const detectIndex = body.indexOf('- name: Detect package manager'); const setupPnpmIndex = body.indexOf('- name: Set up pnpm'); - const setupNodeIndex = body.search(/- uses: actions/setup-node@vd+/); + const setupNodeIndex = body.search(/- uses: actions\/setup-node@v\d+/); expect(detectIndex).toBeGreaterThan(-1); expect(setupPnpmIndex).toBeGreaterThan(detectIndex); @@ -34,7 +34,7 @@ describe('node-ci workflow package-manager setup', () => { it('installs pnpm before setup-node enables pnpm caching', () => { const body = readWorkflow('node-ci'); - expect(body).toMatch(/uses: pnpm/action-setup@vd+/); + expect(body).toMatch(/uses: pnpm\/action-setup@v\d+/); expect(body).toContain("if: steps.pm.outputs.manager == 'pnpm'"); expect(body).toContain('version: ${{ inputs.pnpm-version }}'); expect(body).toContain('run_install: false');