chore(deps): bump the github-actions group across 1 directory with 3 updates #48
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Action Smoke | |
| # Runs the composite Action (action.yml) end-to-end against this repo so its | |
| # ~340 lines of shell are actually exercised, not just shellchecked (that is the | |
| # Lint workflow). The Action fetches the CLI with `npx @clerk/break-check@<ver>`; | |
| # since the package is not on npm yet, we build + pack this checkout and point | |
| # `break-check-version` at the local tarball (a `file:` spec npx accepts), so the | |
| # real Action wiring runs against the real CLI build. Self-dogfood: base-ref is | |
| # the previous commit (or the PR base) and the current side is the workspace. | |
| on: | |
| push: | |
| branches: | |
| - main | |
| pull_request: | |
| paths: | |
| - "action.yml" | |
| - ".github/workflows/action-smoke.yml" | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: action-smoke-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| smoke: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 25 | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| with: | |
| persist-credentials: false | |
| # Full history so the Action can resolve base-ref to a real commit and | |
| # snapshot it in a worktree (mirrors how a consumer checks out). | |
| fetch-depth: 0 | |
| - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6.0.9 | |
| - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| with: | |
| node-version: "24" | |
| cache: "pnpm" | |
| - run: pnpm install --frozen-lockfile | |
| - name: Build and pack the local CLI | |
| id: pack | |
| run: | | |
| set -euo pipefail | |
| pnpm build | |
| # Pack into RUNNER_TEMP to keep the workspace clean; the `file:` spec is | |
| # absolute so it resolves no matter which checkout npx runs from. | |
| file=$(npm pack --pack-destination "$RUNNER_TEMP" --silent | tail -1) | |
| echo "spec=file:$RUNNER_TEMP/$file" >> "$GITHUB_OUTPUT" | |
| - name: Run the Action against this repo | |
| id: smoke | |
| uses: ./ | |
| with: | |
| # On push/dispatch there is no PR base, so diff against the previous | |
| # commit; on a PR, diff against the PR base. | |
| base-ref: ${{ github.event.pull_request.base.sha || 'HEAD~1' }} | |
| # Empty head-ref builds the checked-out workspace as the current side. | |
| head-ref: "" | |
| break-check-version: ${{ steps.pack.outputs.spec }} | |
| comment: "false" | |
| fail-on-breaking: "false" | |
| - name: Assert the Action produced a report and wired its outputs | |
| env: | |
| REPORT_PATH: ${{ steps.smoke.outputs.report-path }} | |
| HAS_BREAKING: ${{ steps.smoke.outputs.has-breaking-changes }} | |
| run: | | |
| set -euo pipefail | |
| echo "has-breaking-changes=$HAS_BREAKING" | |
| echo "report-path=$REPORT_PATH" | |
| if [ -z "$REPORT_PATH" ] || [ ! -s "$REPORT_PATH" ]; then | |
| echo "::error::Action did not produce a non-empty report." | |
| exit 1 | |
| fi | |
| case "$HAS_BREAKING" in | |
| true | false) ;; | |
| *) | |
| echo "::error::has-breaking-changes output was '$HAS_BREAKING', expected true/false." | |
| exit 1 | |
| ;; | |
| esac | |
| echo "Action smoke OK: report at $REPORT_PATH" |