From 442b0f93377ebdba8cfdcc3feac2a4ec7398d3e0 Mon Sep 17 00:00:00 2001 From: DoodlesEpic Date: Sun, 20 Sep 2026 16:27:48 -0300 Subject: [PATCH] ci: use stable version tags for GitHub Actions --- .github/workflows/build.yml | 22 +++++++++++----------- .github/workflows/codeql.yml | 10 +++++----- .github/workflows/dependency-review.yml | 4 ++-- .github/workflows/main.yml | 4 ++-- docs/ci.md | 6 ++++-- 5 files changed, 24 insertions(+), 22 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 9ab4477..0ccece7 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -11,17 +11,17 @@ jobs: runs-on: ubuntu-22.04 timeout-minutes: 40 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 with: fetch-depth: 0 - name: Install native build dependencies run: | sudo apt-get update sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf - - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + - uses: dtolnay/rust-toolchain@v1 with: toolchain: 1.98.1 - - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + - uses: Swatinem/rust-cache@v2 with: workspaces: ./src-tauri -> target key: performance @@ -31,7 +31,7 @@ jobs: run: python3 scripts/benchmark.py - name: Upload performance evidence if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7 with: name: performance-results path: test-results/performance/ @@ -54,22 +54,22 @@ jobs: env: CARGO_BUILD_TARGET: ${{ matrix.target }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 - name: Install Linux dependencies if: runner.os == 'Linux' run: | sudo apt-get update sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf squashfs-tools webkit2gtk-driver xvfb dbus-x11 python3-gi gir1.2-gtk-3.0 - - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + - uses: actions/setup-node@v7 with: node-version: 24 - run: corepack enable - - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + - uses: dtolnay/rust-toolchain@v1 with: toolchain: 1.98.1 targets: ${{ matrix.target }} components: rustfmt, clippy - - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + - uses: Swatinem/rust-cache@v2 with: workspaces: ./src-tauri -> target key: ${{ matrix.target }} @@ -79,7 +79,7 @@ jobs: if: runner.os == 'Linux' run: cargo fmt --manifest-path src-tauri/Cargo.toml --check - name: Build desktop packages - uses: tauri-apps/tauri-action@1deb371b0cd8bd54025b384f1cd735e725c4060f # v1.0.0 + uses: tauri-apps/tauri-action@v1 with: args: --target ${{ matrix.target }} -- --locked - name: Test Rust code @@ -101,7 +101,7 @@ jobs: cd src-tauri/target/${{ matrix.target }}/release/bundle/macos tar -czf "Graph.Prime_${{ matrix.target }}.app.tar.gz" "Graph Prime.app" - name: Upload verified packages - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7 with: name: packages-${{ matrix.target }} if-no-files-found: error @@ -115,7 +115,7 @@ jobs: src-tauri/target/**/release/bundle/nsis/*.exe - name: Upload Linux test evidence if: always() && runner.os == 'Linux' - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7 with: name: linux-smoke-results path: test-results/ diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ec5a89b..6e2d673 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -29,17 +29,17 @@ jobs: matrix: language: [actions, javascript-typescript, python, rust] steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 - name: Install Rust build-script dependencies if: matrix.language == 'rust' run: | sudo apt-get update sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf - - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + - uses: dtolnay/rust-toolchain@v1 if: matrix.language == 'rust' with: toolchain: 1.98.1 - - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + - uses: actions/setup-node@v7 if: matrix.language == 'rust' with: node-version: 24 @@ -47,11 +47,11 @@ jobs: if: matrix.language == 'rust' run: corepack enable && yarn install --immutable && yarn build - name: Initialize CodeQL - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} build-mode: none - name: Analyze - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/analyze@v4 with: category: /language:${{ matrix.language }} diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 013122d..62dc0f7 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -15,9 +15,9 @@ jobs: runs-on: ubuntu-latest steps: - name: "Checkout Repository" - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7 - name: "Dependency Review" - uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0 + uses: actions/dependency-review-action@v5.0.0 with: # Fail the PR when a newly introduced dependency has this severity or higher fail-on-severity: moderate diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 38e1d14..6221116 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -23,7 +23,7 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 - name: Verify release version env: RELEASE_TAG: ${{ github.ref_name }} @@ -31,7 +31,7 @@ jobs: test "$RELEASE_TAG" = "v$(node -p 'require("./package.json").version')" test "$RELEASE_TAG" = "v$(node -p 'require("./src-tauri/tauri.conf.json").version')" test -s "docs/releases/$RELEASE_TAG.md" - - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + - uses: actions/download-artifact@v8 with: pattern: packages-* path: packages diff --git a/docs/ci.md b/docs/ci.md index 00216db..2ab152f 100644 --- a/docs/ci.md +++ b/docs/ci.md @@ -15,8 +15,10 @@ so the embedded assets exist. Linux additionally requires Rust formatting, Clipp and the packaged AppImage GUI smoke test. Performance comparisons run in a separate job and must pass before a release can upload packages. -External actions are pinned to commit SHAs with version comments. Update the SHA -and comment together after checking the upstream release notes. +External actions use stable major-version tags where available. Dependency Review +uses `v5.0.0` because upstream does not publish a `v5` tag. Check official releases +and tag references before changing versions. Rust remains fixed at 1.98.1 through +the toolchain inputs, independently of the installer action version. ## CodeQL