diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 40f3f02..e5542b2 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -25,10 +25,10 @@ jobs: if: github.event_name == 'schedule' timeout-minutes: 5 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version-file: ".nvmrc" cache: "npm" @@ -39,7 +39,7 @@ jobs: run: npx vitest run src/lib/*.fuzz.test.ts - name: Upload corpus artifacts if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fuzz-corpus path: src/test/fuzz-corpus/ @@ -75,7 +75,7 @@ jobs: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Post dependency diff report as PR comment if: github.event_name == 'pull_request' - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const fs = require('fs'); @@ -109,10 +109,10 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version-file: '.nvmrc' cache: 'npm' @@ -126,7 +126,7 @@ jobs: else echo "No base coverage artifact is committed; establishing the baseline." fi - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() with: name: coverage-report @@ -136,7 +136,7 @@ jobs: - name: Check the e2e suite resolves run: npm run test:e2e -- --list - run: npm run test:e2e - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() with: name: playwright-report @@ -149,15 +149,15 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version-file: '.nvmrc' cache: 'npm' - name: Restore Next.js build cache - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: .next/cache key: ${{ runner.os }}-next-${{ hashFiles('**/package-lock.json') }}-${{ github.sha }} @@ -188,15 +188,15 @@ jobs: matrix: browser: ${{ github.event_name == 'pull_request' && fromJSON('["chromium"]') || fromJSON('["chromium","firefox","webkit"]') }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version-file: '.nvmrc' cache: 'npm' - name: Cache Playwright browsers - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: ~/.cache/ms-playwright key: ${{ runner.os }}-playwright-${{ hashFiles('**/package-lock.json') }} @@ -215,7 +215,7 @@ jobs: echo '### Flaky tests' >> $GITHUB_STEP_SUMMARY cat playwright-report/flaky.json >> $GITHUB_STEP_SUMMARY fi - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() with: name: playwright-report-${{ matrix.browser }} @@ -230,15 +230,15 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version-file: '.nvmrc' cache: 'npm' - name: Cache Playwright browsers - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: ~/.cache/ms-playwright key: ${{ runner.os }}-playwright-${{ hashFiles('**/package-lock.json') }} @@ -250,7 +250,7 @@ jobs: run: node scripts/generate-sbom.mjs sbom.json - name: Upload SBOM artifact if: github.ref == 'refs/heads/main' - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: sbom path: sbom.json @@ -266,7 +266,7 @@ jobs: npm run test:storybook - name: Run visual regression tests run: npm run test:visual - - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a - name: Build Storybook run: npm run build:storybook - name: Run Storybook accessibility tests @@ -288,9 +288,9 @@ jobs: name: E2E (Playwright) runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version-file: '.nvmrc' cache: 'npm' @@ -304,7 +304,7 @@ jobs: run: npm ls --all > /dev/null - name: Generate SBOM run: npx --yes @cy - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version-file: '.nvmrc' cache: 'npm' @@ -315,10 +315,10 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version-file: '.nvmrc' cache: 'npm' @@ -332,7 +332,7 @@ jobs: run: npm ls --all > /dev/null - name: Generate SBOM run: npx --yes @cyclonedx/cyclonedx-npm --output-file sbom.json - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() with: name: sbom @@ -343,8 +343,8 @@ jobs: name: E2E (Playwright) runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-node@v7 with: node-version-file: '.nvmrc' cache: 'npm' @@ -354,7 +354,7 @@ jobs: run: echo "version=$(npx playwright --version | awk '{print $2}')" >> "$GITHUB_OUTPUT" - name: Cache Playwright browsers id: playwright-cache - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: ~/.cache/ms-playwright key: playwright-${{ runner.os }}-${{ steps.playwright-version.outputs.version }}-chromium @@ -366,7 +366,7 @@ jobs: run: npx playwright install-deps chromium - name: Run Playwright tests run: npm run test:e2e -- --project=chromium - - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() with: name: playwright-report diff --git a/.github/workflows/coverage-badge.yml b/.github/workflows/coverage-badge.yml index cb3c12f..fdfca2c 100644 --- a/.github/workflows/coverage-badge.yml +++ b/.github/workflows/coverage-badge.yml @@ -22,12 +22,12 @@ jobs: if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }} steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: ref: ${{ github.event.workflow_run.head_branch || github.ref }} - name: Setup Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: 20 cache: npm diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index ad87d57..f51b957 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -51,7 +51,7 @@ jobs: run: node scripts/generate-sbom.mjs sbom.json - name: Upload SBOM artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: sbom path: sbom.json @@ -84,7 +84,7 @@ jobs: path: .next - name: Download SBOM artifact - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: sbom path: . diff --git a/.github/workflows/preview-deploy.yml b/.github/workflows/preview-deploy.yml index e51f7c7..c0e8ba7 100644 --- a/.github/workflows/preview-deploy.yml +++ b/.github/workflows/preview-deploy.yml @@ -155,12 +155,12 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: ref: ${{ github.event.pull_request.head.sha }} - name: Setup Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: 20 cache: 'npm' @@ -204,7 +204,7 @@ jobs: - name: Upload Playwright traces on failure if: steps.smoke.outputs.smoke-failed == 'true' || failure() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: playwright-traces-${{ github.event.pull_request.number }} path: | @@ -243,7 +243,7 @@ jobs: - name: Upload visual diff bundle if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: visual-diff-${{ github.event.pull_request.number }} path: visual-diff/ @@ -252,7 +252,7 @@ jobs: - name: Upload Lighthouse report if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: lighthouse-report-${{ github.event.pull_request.number }} path: lighthouse-report/ @@ -261,7 +261,7 @@ jobs: - name: Build consolidated report and upsert sticky comment if: always() - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: PREVIEW_URL: ${{ needs.deploy-preview.outputs.deployment-url }} SMOKE_FAILED: ${{ steps.smoke.outputs.smoke-failed }}