Commit Graph

8 Commits

Author SHA1 Message Date
Sebastian "Sebbie" Silbermann 52cd5b96ab Skip discussions in the issue_lock workflow (#98146)
The last remaining `Lock Threads` failures are likely due to missing
permissions for discussions which `dessant/lock-threads` handles by
default.

This disables discussion handling to get the workflow green to start
tracking regressions. We can discuss if we want to lock inactive
discussions in a follow-up (which would be new behavior this workflow
never performed).

Co-authored-by: Claude Code (kimi-k3[1m]) <noreply@anthropic.com>
2026-09-01 18:06:18 +00:00
Sebastian "Sebbie" Silbermann 3866d6fd2b [ci] Fix issue_lock (#97755)
Fixes
> "github-token" length must be less than or equal to 100 characters
long
-- https://github.com/vercel/next.js/actions/runs/33188474239

GitHub uses stateless tokens now which are way longer. See
https://github.com/dessant/lock-threads/issues/55

---------

Co-authored-by: Claude Code (kimi-k3[1m]) <noreply@anthropic.com>
2026-09-01 17:50:10 +02:00
dagecko f7de136c60 fix: pin 19 actions to commit SHA, extract 7 expressions to env vars (#92016)
Re-submission of #91933. Had a problem with my fork and had to delete
it, which closed the original PR. Apologies for the noise.

## Summary

This PR pins all GitHub Actions to immutable commit SHAs instead of
mutable version tags and extracts expressions from `run:` blocks into
`env:` mappings.

- Pin 19 unpinned actions across workflow files to full 40-character
SHAs
- Add version comments for readability (e.g., `@abc123 # v1.0.9`)
- Extract 2 secrets and 5 workflow_dispatch inputs from run blocks to
env vars

## Changes by file

| File | Changes |
|------|---------|
| build_and_deploy.yml | Pinned ijjk/rust-cache, ast-grep/action,
taiki-e/install-action to SHA |
| build_reusable.yml | Pinned ijjk/rust-cache,
SimenB/github-actions-cpu-cores to SHA |
| cancel.yml | Pinned withgraphite/graphite-ci-action to SHA, extracted
GRAPHITE_TOKEN to env var |
| lock.yml | Pinned dessant/lock-threads to SHA |
| notify_slack.yml | Pinned slackapi/slack-github-action to SHA (2
instances) |
| publish_canary.yml | Extracted NPM_TOKEN_ELEVATED to env var |
| publish_release.yml | Extracted 5 workflow_dispatch inputs to env vars
|
| retry_deploy_test.yml | Pinned dtolnay/rust-toolchain to SHA |
| triage.yml | Pinned balazsorban44/nissuer to SHA |
| turbopack_benchmark.yml | Pinned taiki-e/install-action,
ijjk/rust-cache, CodSpeedHQ/action to SHA |
| turbopack_benchmark_wasm.yml | Pinned taiki-e/install-action,
CodSpeedHQ/action to SHA |
| turbopack_benchmark_xtask.yml | Pinned taiki-e/install-action,
CodSpeedHQ/action to SHA |

## Actions Pinned

| Action | Version | SHA |
|--------|---------|-----|
| ijjk/rust-cache | turbo-cache-v1.0.9 | a34594c45081... |
| ast-grep/action | v1.5.0 | cf62e780f0c8... |
| taiki-e/install-action | nextest / v2 | 3a0adb... / 7627fb... |
| withgraphite/graphite-ci-action | main | ee395f3a7825... |
| dessant/lock-threads | v5 | 1bf7ec25051f... |
| slackapi/slack-github-action | v1.25.0 | 6c661ce58804... |
| SimenB/github-actions-cpu-cores | v2 | 97ba232459a8... |
| dtolnay/rust-toolchain | stable | 631a55b12751... |
| balazsorban44/nissuer | 1.10.0 | 92ef22afd6a7... |
| CodSpeedHQ/action | v4 | 1c8ae4843586... |

## A note on internal action pinning

This PR pins all actions including org-owned ones. Best practice is to
pin everything \u2014 the tj-actions/changed-files attack was an
internally maintained action that was compromised, and every repo
referencing it by tag silently executed attacker code. That said, it's
your codebase. If you'd prefer to leave org-owned actions unpinned, let
us know and we'll adjust the PR.

## How to verify

Review the diff \u2014 each change is mechanical and preserves workflow
behavior:
- **SHA pinning**: `action@v3` becomes `action@abc123 # v3` \u2014
original version preserved as comment
- **Expression extraction**: `${{ expr }}` in `run:` moves to `env:`
block, referenced as `$ENV_VAR` in the script
- No workflow logic, triggers, or permissions are modified

I put up some research on this on
[Twitter](https://x.com/vigilance_one/status/2036581210663616729) and a
[research
site](https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan)
if you want more context. I wrote a scanner called Runner Guard and open
sourced it [here](https://github.com/Vigilant-LLC/runner-guard).

If you have any questions, reach out. I'll be monitoring comms.

\\- Chris Nyhuis (dagecko)

---------

Co-authored-by: Benjamin Woodruff <github@benjam.info>
Co-authored-by: Benjamin Woodruff <benjamin.woodruff@vercel.com>
2026-04-01 00:57:59 +00:00
Leah 1240cda484 chore: update github actions (#61517)
### Why?

They used the `node16` runner which is deprecated

### Notable breaking changes

#### `dessant/lock-threads@v5`
[link](https://github.com/dessant/lock-threads)

Now also locks discussions (in addition to issues and pull requests):
https://github.com/dessant/lock-threads/blob/main/CHANGELOG.md#500-2023-11-14

#### `actions/stale@v9` [link](https://github.com/actions/stale)

Is now stateful: If the action ends because of
[operations-per-run](https://github.com/actions/stale#operations-per-run)
then the next run will start from the first unprocessed issue skipping
the issues processed during the previous run(s).
https://github.com/actions/stale/releases/tag/v9.0.0


Closes PACK-2347

Co-authored-by: Tobias Koppers <tobias.koppers@googlemail.com>
2024-02-01 22:13:29 +01:00
Balázs Orbán a6415c6297 chore: update lock bot wording (#54099)
Follow-up of #54048. We changed the lock action from waiting 1 month to 2 weeks, but the wording was not reflecting it.
2023-08-16 09:05:04 +00:00
Balázs Orbán 633b553842 chore: hide "same on new version" without link (#54048)
Chat with @timneutkens

- Lock closed issues after 14 days of inactivity
- Hide comments "still happening" without a link we can verify
2023-08-15 09:44:07 +00:00
Balázs Orbán 4ddb6fc794 chore: add label to locked threads (#52497)
[Slack
thread](https://vercel.slack.com/archives/C04DUD7EB1B/p1688975623048229)

Docs: https://github.com/dessant/lock-threads#inputs

Co-authored-by: kodiakhq[bot] <49736102+kodiakhq[bot]@users.noreply.github.com>
2023-07-10 14:59:23 +02:00
Balázs Orbán 4ee933db92 chore: add issue labeler (#43599)
Follow-up of #43228. This PR adds a new [GitHub Action](https://github.com/github/issue-labeler) that matches the
issue's body for the [dropdown list items](https://github.com/vercel/next.js/blame/6cacd5a7c46fb1bb86c536031140da92863ce451/.github/ISSUE_TEMPLATE/1.bug_report.yml#L26-L48) and adds the relevant labels to the issue for triaging automatically.
2022-12-01 12:00:42 +00:00