Skip to content

Commit 34061a8

Browse files
committed
Pin checkout and setup-node to commits in the release job
Every action in the job that holds the npm trusted-publishing identity and a write-scoped token is now referenced by commit, so none of the code it runs can change under a moved tag. Both move from v4 to v7. The breaking changes across those majors do not reach this workflow: setup-node's automatic package-manager caching keys off a packageManager field in package.json, which this project does not set, and its removal of the dummy NODE_AUTH_TOKEN export only affects token-based publishing rather than the OIDC path used here. checkout's fork-checkout restriction applies to pull_request_target and workflow_run, neither of which triggers this workflow, and its move to storing credentials outside .git/config narrows what a later step in the job can read.
1 parent c5fae5d commit 34061a8

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@ jobs:
1212
contents: write
1313
id-token: write
1414
steps:
15-
- uses: actions/checkout@v4
16-
- uses: actions/setup-node@v4
15+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
16+
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
1717
with:
1818
node-version: '22'
1919
registry-url: 'https://registry.npmjs.org'

0 commit comments

Comments
 (0)