Repository navigation
Commit 34061a8
committed
Pin checkout and setup-node to commits in the release job
Every action in the job that holds the npm trusted-publishing identity and a
write-scoped token is now referenced by commit, so none of the code it runs can
change under a moved tag.
Both move from v4 to v7. The breaking changes across those majors do not reach
this workflow: setup-node's automatic package-manager caching keys off a
packageManager field in package.json, which this project does not set, and its
removal of the dummy NODE_AUTH_TOKEN export only affects token-based publishing
rather than the OIDC path used here. checkout's fork-checkout restriction
applies to pull_request_target and workflow_run, neither of which triggers this
workflow, and its move to storing credentials outside .git/config narrows what
a later step in the job can read.1 parent c5fae5d commit 34061a8
1 file changed
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
16 | | - | |
| 15 | + | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
0 commit comments