ci: harden GitHub Actions workflows (#1156)

Co-authored-by: Codex <noreply@openai.com>
This commit is contained in:
Shohei UedaandCodex authored and GitHub committed 2026-05-13 00:56:32 +09:00
1 parent 31835fbbe3
commit aa0466c179
10 files changed
+60 -42

No files matched your search

+11 -11
View File
@@ -1,27 +1,27 @@
cicd: cicd:
- changed-files: - changed-files:
- any-glob-to-any-file: .github/workflows/* - any-glob-to-any-file: '.github/workflows/*'
dependencies: dependencies:
- changed-files: - changed-files:
- any-glob-to-any-file: - any-glob-to-any-file:
- .nvmrc - '.nvmrc'
- package.json - 'package.json'
- package-lock.json - 'package-lock.json'
documentation: documentation:
- changed-files: - changed-files:
- any-glob-to-any-file: README.md - any-glob-to-any-file: 'README.md'
test: test:
- changed-files: - changed-files:
- any-glob-to-any-file: __tests__ - any-glob-to-any-file: '__tests__/**'
docker: docker:
- changed-files: - changed-files:
- any-glob-to-any-file: - any-glob-to-any-file:
- .devcontainer/* - '.devcontainer/*'
- .dockerignore - '.dockerignore'
- Dockerfile - 'Dockerfile'
- Makefile - 'Makefile'
- docker-compose.yml - 'docker-compose.yml'
+11 -4
View File
@@ -6,19 +6,26 @@ on:
- main - main
pull_request: pull_request:
permissions:
actions: read
contents: read
packages: read
security-events: write
jobs: jobs:
CodeQL-Build: CodeQL-Build:
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
timeout-minutes: 20
steps: steps:
- uses: actions/checkout@v6 - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Initialize CodeQL - name: Initialize CodeQL
uses: github/codeql-action/init@v4 uses: github/codeql-action/init@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
with: with:
languages: javascript languages: javascript
- name: Autobuild - name: Autobuild
uses: github/codeql-action/autobuild@v4 uses: github/codeql-action/autobuild@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
- name: Perform CodeQL Analysis - name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4 uses: github/codeql-action/analyze@68bde559dea0fdcac2102bfdf6230c5f70eb485e # v4.35.4
+4 -3
View File
@@ -10,7 +10,8 @@ permissions:
jobs: jobs:
dependency-review: dependency-review:
runs-on: ubuntu-24.04 runs-on: ubuntu-slim
timeout-minutes: 5
steps: steps:
- uses: actions/checkout@v6 - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/dependency-review-action@v5.0.0 - uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
+4 -3
View File
@@ -17,11 +17,12 @@ permissions:
jobs: jobs:
comment: comment:
runs-on: ubuntu-24.04 runs-on: ubuntu-slim
timeout-minutes: 5
steps: steps:
- uses: actions/checkout@v6 - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Label Commenter - name: Label Commenter
uses: peaceiris/actions-label-commenter@v1 uses: peaceiris/actions-label-commenter@f0dbbef043eb1b150b566db36b0bdc8b7f505579 # v1.10.0
env: env:
RUNNER_DEBUG: 1 RUNNER_DEBUG: 1
+4 -4
View File
@@ -5,18 +5,18 @@ on:
jobs: jobs:
triage: triage:
runs-on: ubuntu-24.04 runs-on: ubuntu-slim
timeout-minutes: 1 timeout-minutes: 5
permissions: {} permissions: {}
steps: steps:
# https://github.com/peaceiris/actions-github-app-token # https://github.com/peaceiris/actions-github-app-token
- uses: peaceiris/actions-github-app-token@v1.1.6 - uses: peaceiris/actions-github-app-token@652b86006ad2c113bdd5c478c9a98f359829847b # v1.1.6
id: app id: app
with: with:
app_id: ${{ secrets.GH_APP_ID }} app_id: ${{ secrets.GH_APP_ID }}
private_key: ${{ secrets.GH_APP_PRIVATE_KEY }} private_key: ${{ secrets.GH_APP_PRIVATE_KEY }}
# https://github.com/actions/labeler # https://github.com/actions/labeler
- uses: actions/labeler@v6 - uses: actions/labeler@f27b608878404679385c85cfa523b85ccb86e213 # v6.1.0
with: with:
repo-token: "${{ steps.app.outputs.token }}" repo-token: "${{ steps.app.outputs.token }}"
+3 -1
View File
@@ -4,7 +4,9 @@ on: page_build
jobs: jobs:
pages-status-check: pages-status-check:
runs-on: ubuntu-24.04 runs-on: ubuntu-slim
timeout-minutes: 5
permissions: {}
steps: steps:
- name: check status - name: check status
run: | run: |
@@ -8,10 +8,11 @@ on:
jobs: jobs:
purge: purge:
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
timeout-minutes: 5
permissions: {}
steps: steps:
- run: > - run: >
curl -sL https://github.com/${GITHUB_REPOSITORY} | curl -sL "https://github.com/${GITHUB_REPOSITORY}" |
grep -oE '<img src="https?://camo.githubusercontent.com/[^"]+' | grep -oE '<img src="https?://camo.githubusercontent.com/[^"]+' |
sed -e 's/<img src="//' | sed -e 's/<img src="//' |
xargs -I % curl -sX PURGE % xargs -I % curl -sX PURGE "%"
+5 -2
View File
@@ -8,9 +8,12 @@ on:
jobs: jobs:
release: release:
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: write
steps: steps:
- uses: actions/checkout@v6 - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# https://github.com/peaceiris/workflows/blob/main/create-release-npm/action.yml # https://github.com/peaceiris/workflows/blob/main/create-release-npm/action.yml
- uses: peaceiris/workflows/create-release-npm@v0.21.6 - uses: peaceiris/workflows/create-release-npm@99f66a30a38f806fd0df9014275c7cef0b6d9ca5 # v0.21.6
env: env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+9 -8
View File
@@ -17,6 +17,7 @@ concurrency:
jobs: jobs:
test: test:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
timeout-minutes: 30
strategy: strategy:
matrix: matrix:
os: os:
@@ -28,9 +29,9 @@ jobs:
permissions: permissions:
contents: write contents: write
steps: steps:
- uses: actions/checkout@v6 - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/setup-node@v6 - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with: with:
node-version-file: ".nvmrc" node-version-file: ".nvmrc"
cache: 'npm' cache: 'npm'
@@ -44,7 +45,7 @@ jobs:
- run: npm ci --ignore-scripts - run: npm ci --ignore-scripts
- name: npm audit - name: npm audit
if: startsWith(matrix.os, 'ubuntu-22.04') if: startsWith(matrix.os, 'ubuntu-24.04')
run: | run: |
npm audit > ./audit.log || true npm audit > ./audit.log || true
if ! [ "$(cat ./audit.log | wc -l)" = 1 ]; then if ! [ "$(cat ./audit.log | wc -l)" = 1 ]; then
@@ -53,22 +54,22 @@ jobs:
rm ./audit.log rm ./audit.log
- name: Run prettier - name: Run prettier
if: startsWith(matrix.os, 'ubuntu-22.04') if: startsWith(matrix.os, 'ubuntu-24.04')
run: npm run format:check run: npm run format:check
- name: Run eslint - name: Run eslint
if: startsWith(matrix.os, 'ubuntu-22.04') if: startsWith(matrix.os, 'ubuntu-24.04')
run: npm run lint run: npm run lint
- run: npm test - run: npm test
- name: Upload test coverage as artifact - name: Upload test coverage as artifact
uses: actions/upload-artifact@v7 uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with: with:
name: coverage-${{ matrix.os }} name: coverage-${{ matrix.os }}
path: coverage path: coverage
- uses: codecov/codecov-action@v4 - uses: codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4.6.0
- name: Run build - name: Run build
run: npm run build run: npm run build
@@ -81,7 +82,7 @@ jobs:
- name: Setup mdBook - name: Setup mdBook
if: ${{ github.ref == 'refs/heads/main' }} if: ${{ github.ref == 'refs/heads/main' }}
uses: peaceiris/actions-mdbook@v2.0.0 uses: peaceiris/actions-mdbook@ee69d230fe19748b7abf22df32acaa93833fad08 # v2.0.0
with: with:
mdbook-version: '0.4.5' mdbook-version: '0.4.5'
+5 -3
View File
@@ -6,10 +6,12 @@ on:
jobs: jobs:
update: update:
runs-on: ubuntu-24.04 runs-on: ubuntu-slim
timeout-minutes: 1 timeout-minutes: 5
permissions:
contents: write
steps: steps:
- uses: actions/checkout@v6 - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Update major tag - name: Update major tag
run: | run: |