chore(ci): bump GitHub Actions to current majors (#237)
* chore(ci): bump GitHub Actions to current majors Node 20 action runtimes are deprecated on GitHub runners; bump every first-party action to its latest major across all workflows: - actions/checkout v4/v6 -> v7 - actions/cache v4 -> v6 - actions/upload-artifact v4 -> v7, download-artifact v4 -> v8 - actions/setup-node v6 -> v7, setup-python v5 -> v7 - actions/upload-pages-artifact v3 -> v5, deploy-pages v4 -> v5 Third-party pins (dtolnay/rust-toolchain, Swatinem/rust-cache, setup-zig, setup-bun, taiki-e/install-action, maturin-action) are already on their latest majors. * chore(ci): pin all actions to full commit SHAs Mutable @vN tags can be retagged; in the publish workflows that code runs with OIDC credentials before npm/PyPI/crates.io publishes. Pin every action (first- and third-party) to its release commit SHA with the version in a trailing comment. dtolnay/rust-toolchain infers the toolchain from its ref name, so the SHA-pinned invocations pass an explicit toolchain: stable input.
This commit is contained in:
@@ -24,7 +24,7 @@ jobs:
|
||||
published: ${{ steps.check.outputs.published }}
|
||||
version: ${{ steps.check.outputs.version }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 2
|
||||
|
||||
@@ -71,14 +71,15 @@ jobs:
|
||||
contents: read
|
||||
id-token: write
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Install Rust
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
uses: dtolnay/rust-toolchain@4cda84d5c5c54efe2404f9d843567869ab1699d4 # stable
|
||||
with:
|
||||
toolchain: stable
|
||||
targets: wasm32-unknown-unknown
|
||||
|
||||
- uses: actions/setup-node@v6
|
||||
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: '24'
|
||||
registry-url: 'https://registry.npmjs.org'
|
||||
|
||||
Reference in New Issue
Block a user