Commit Graph

10 Commits

Author SHA1 Message Date
Nathan Nguyen 8ad5e5be32 fix(ci): resolve setup-vp version from catalog (#2406)
* fix(ci): resolve setup-vp version from catalog

* ci: retry app-router e2e

* fix(ci): avoid heredoc in setup version resolver

* fix(ci): anchor setup resolver to workspace root

* chore: rerun ci

* chore: rerun ci
2026-06-29 17:44:05 +01:00
Jerry Zhao fb9151ed9d chore(deps): bump vite-plus toolchain to 0.1.24 (#1767)
* chore(deps): bump vite-plus toolchain to 0.1.24

* bump setup-vp

* .

---------

Co-authored-by: James <james@eli.cx>
2026-06-05 15:36:59 +00:00
James Anderson 601a394582 ci: address zizmor security audit findings (#1577)
* ci: address zizmor security audit findings

Run `zizmor .` and address all findings:

- Pin actions to commit SHAs with version comments (unpinned-uses).
  Dependabot picks up the version comment for future bumps.
- Move `contents: write` / `id-token: write` to the publish job in
  publish.yml; set `permissions: {}` at the workflow level
  (excessive-permissions).
- Add `permissions: {}` to deploy-examples.yml workflow + scope
  smoke-test job to `contents: read` (excessive-permissions).
- Move `${{ ... }}` expansions inside run blocks into `env:` vars
  in publish.yml / benchmarks.yml / nextjs-deploy-suite.yml
  (template-injection).
- Set `persist-credentials: false` on all checkouts that don't push;
  publish.yml needs them for `git push origin v$VERSION`, so it
  carries an inline `zizmor: ignore[artipacked]` instead.
- Keep dependabot's 1-day cooldown but annotate with `zizmor: ignore`
  (intentional fast cooldown).

`zizmor .` is now clean.

* ci: add zizmor GitHub Actions workflow

Run zizmor on every push to main and every PR via the upstream
`zizmorcore/zizmor-action`. Findings surface in the GitHub Code
Scanning UI (Security → Code scanning alerts).

* ci(publish): explain zizmor artipacked ignore
2026-05-22 19:41:30 +01:00
James Anderson fe700996d9 ci: extract Playwright cache plumbing into a composite action (#1438)
Two workflows now share an identical playwright-version + cache-restore
pattern: ci.yml (which owns the cache, used by E2E jobs) and
nextjs-deploy-suite.yml (which restores it read-only, added in #1435).
Pull the duplication into .github/actions/playwright-cache so the cache
key format can't drift between the two callers — if it ever does, the
deploy-suite stops hitting ci.yml's cache and the upstream Playwright
extraction hang from 2026-05-22 (runs 26265986264 .. 26281758803)
reappears.

The composite action:
- Reads the playwright version from a configurable lockfile path
  (`lockfile` input, defaults to pnpm-lock.yaml).
- Restores ~/.cache/ms-playwright keyed
  `playwright-${browser}-${runner.os}-v${version}`.
- Supports two modes: `cache` (restore + save, default — for the workflow
  that owns the cache) and `restore` (read-only — for downstream
  consumers that don't want to fight over the save).
- Exposes `cache-hit`, `version`, and `key` outputs so callers can gate
  install steps or use the version for sibling cache keys (e.g. ci.yml's
  apt-archives cache for WebKit deps).

No behavioural change — same cache keys, same restore-keys, same
~/.cache/ms-playwright path.
2026-05-22 11:15:37 +00:00
James Anderson 746d6b5970 chore(ci): bump Node to 24 for native URLPattern support (#1283) 2026-05-16 19:33:46 +01:00
James Anderson 0f05e53f1f bump setup-vp (#1135) 2026-05-07 14:35:08 +00:00
dependabot[bot] 41d363e8b2 chore(deps): bump vite-plus from 0.1.12 to 0.1.17 (#858)
* chore(deps): bump vite-plus from 0.1.12 to 0.1.17

Bumps [vite-plus](https://github.com/voidzero-dev/vite-plus/tree/HEAD/packages/cli) from 0.1.12 to 0.1.17.
- [Release notes](https://github.com/voidzero-dev/vite-plus/releases)
- [Commits](https://github.com/voidzero-dev/vite-plus/commits/v0.1.17/packages/cli)

---
updated-dependencies:
- dependency-name: vite-plus
  dependency-version: 0.1.17
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* bump setup-vp

* update agents

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: James <james@eli.cx>
2026-04-17 07:43:02 +00:00
Erez Rokah 25bbfa6937 chore: Harden CI supply chain (#826)
* chore: harden CI supply chain

- Pin voidzero-dev/setup-vp to commit SHA across all workflows
- Pin create-next-app and pkg-pr-new to exact versions

* pull setup-vp into setup action

---------

Co-authored-by: James <james@eli.cx>
2026-04-13 08:05:50 +00:00
Stephen Zhou c17d6941be chore: migrate to vite plus (#535)
* chore: migrate to vite plus

* Disable typeAware and typeCheck

* Update CI

* Fix CI

* Fix test

* Clean

* Run test with vp

* Try revert

* react: false In test

* Fix test

* Revert "Try revert"

This reverts commit 009da10473.

* Update

* Update

* Try revert ci changes

* revert

* Run vp migrate

* Disable typeAware and typeCheck for now

* Better resolve for test

* Use vp dev instead of vite

* Update expect

* Fix NormalizeManifestModuleId

* Try increase timeout

* Update to use vp

* Try new check

* Bring back npx vp

* Migrate CI

* Make next-intl resolvable

* Update

* Update

* Update
2026-03-15 10:50:13 +00:00
James Anderson 90771f7b00 refactor(ci): extract composite actions and improve workflow hygiene (#314)
* refactor(ci): extract composite actions and improve workflow hygiene

- Add composite actions: setup-node-pnpm, build-vinext, deploy-example, comment-preview-urls
- Cache Playwright browsers in CI to avoid ~150MB download per E2E run
- Add concurrency group to deploy-examples.yml to prevent deploy pileup
- Replace inline CJS node script in create-next-app job with portable bash
- Convert ecosystem-run.yml inline Node scripts from CJS require() to ESM
- Apply composite actions across all workflows to eliminate repeated boilerplate

* refactor(ci): revert to inline steps, keep only setup-node-pnpm composite action

Remove the build-vinext, deploy-example, and comment-preview-urls composite
actions and inline their steps back into each workflow. Keep setup-node-pnpm
as the one reusable action (pnpm install + node setup). Retain all other
improvements from the previous commit: concurrency groups, Playwright browser
cache, bash-based dev-server check, ESM node scripts in ecosystem-run.

* refactor(ci): use setup-node-pnpm composite action consistently

Every workflow that does pnpm/node setup + install now uses the
setup-node-pnpm composite action instead of the inline 3-step triplet.
Added optional registry-url input to support publish.yml's npm auth.

Exceptions (intentionally kept inline):
- bonk.yml / bigbonk.yml: issue_comment trigger, GHAS constraint
- tip.yml notify-on-failure: node-only, no pnpm install needed
2026-03-07 13:23:34 +00:00