From da78a3c3d8c816b6412a8f033ba6c1e40780a991 Mon Sep 17 00:00:00 2001 From: Rajarshee Chatterjee Date: Tue, 21 Jul 2026 08:46:17 +0530 Subject: [PATCH] chore(ci): Harden Workflows And Pin Actions --- .github/workflows/issue_auto_label.yml | 42 ++++++++++++++------- .github/workflows/lock.yml | 11 ++++-- .github/workflows/prettier.yml | 20 +++++----- .github/workflows/publish-plugins.yml | 11 ++++-- .github/workflows/theme_auto_label.yml | 3 ++ .github/workflows/update-issue-template.yml | 8 ++-- 6 files changed, 59 insertions(+), 36 deletions(-) diff --git a/.github/workflows/issue_auto_label.yml b/.github/workflows/issue_auto_label.yml index efd88ab..c88e9af 100644 --- a/.github/workflows/issue_auto_label.yml +++ b/.github/workflows/issue_auto_label.yml @@ -6,6 +6,8 @@ on: - opened - edited +permissions: {} + concurrency: group: ${{ github.workflow }}-${{ github.event.issue.number }} cancel-in-progress: true @@ -15,15 +17,22 @@ jobs: name: Auto Label Issues if: ${{ github.event.issue.body && contains(github.event.issue.body, '### Plugin') && contains(github.event.issue.labels.*.name, 'Bug') }} runs-on: ubuntu-latest + permissions: + contents: read + issues: write + env: + ISSUE_BODY: ${{ github.event.issue.body }} steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false - name: Extract Severity From Issue Body id: extract-severity run: | - USER_SELECTED_SEVERITY=$(echo "${{ github.event.issue.body }}" | grep "### Severity" -A 2 | tail -n 1 | sed 's/[[:space:]]*$//') + USER_SELECTED_SEVERITY=$(printf '%s\n' "$ISSUE_BODY" | grep "### Severity" -A 2 | tail -n 1 | sed 's/[[:space:]]*$//') SELECTED_SEVERITY="" case "$USER_SELECTED_SEVERITY" in @@ -34,26 +43,26 @@ jobs: SELECTED_SEVERITY="Other" ;; esac - echo "SELECTED_SEVERITY=$SELECTED_SEVERITY" >> $GITHUB_ENV + echo "SELECTED_SEVERITY=$SELECTED_SEVERITY" >> "$GITHUB_ENV" - name: Extract Plugin From Issue Body id: parse-issue run: | - SELECTED_PLUGIN=$(echo "${{ github.event.issue.body }}" | awk '/### Plugin/ {f=1; next} f && NF {print; exit}' | sed 's/^[[:space:]]*//;s/[[:space:]]*$//') + SELECTED_PLUGIN=$(printf '%s\n' "$ISSUE_BODY" | awk '/### Plugin/ {f=1; next} f && NF {print; exit}' | sed 's/^[[:space:]]*//;s/[[:space:]]*$//') - echo "SELECTED_PLUGIN=$SELECTED_PLUGIN" >> $GITHUB_ENV + echo "SELECTED_PLUGIN=$SELECTED_PLUGIN" >> "$GITHUB_ENV" - name: Extract Language From Issue Body id: extract-language run: | - SELECTED_LANGUAGE=$(echo "${{ github.event.issue.body }}" | awk '/### Language/ {f=1; next} f && NF {print; exit}' | sed 's/^[[:space:]]*//;s/[[:space:]]*$//') + SELECTED_LANGUAGE=$(printf '%s\n' "$ISSUE_BODY" | awk '/### Language/ {f=1; next} f && NF {print; exit}' | sed 's/^[[:space:]]*//;s/[[:space:]]*$//') - echo "SELECTED_LANGUAGE=$SELECTED_LANGUAGE" >> $GITHUB_ENV + echo "SELECTED_LANGUAGE=$SELECTED_LANGUAGE" >> "$GITHUB_ENV" - name: Determine Corresponding Label id: determine-label run: | - LABELS="$( jq --arg keys "${{ env.SELECTED_PLUGIN }}" '. as $data | $keys | split(", ") as $keyList | $keyList[] | . as $key | if $data[$key] != null then "\($key)[\($data[$key])]" else empty end' ./.github/scripts/keys.json | sed 's/"//g' | sed 's/^[^:]*: //' )" + LABELS="$(jq --arg keys "$SELECTED_PLUGIN" '. as $data | $keys | split(", ") as $keyList | $keyList[] | . as $key | if $data[$key] != null then "\($key)[\($data[$key])]" else empty end' ./.github/scripts/keys.json | sed 's/"//g' | sed 's/^[^:]*: //')" # Add "Plugin: " in front of each label LABELS_WITH_PREFIX="$(echo "$LABELS" | sed 's/^/Plugin: /')" @@ -65,15 +74,20 @@ jobs: fi # Save to GitHub environment - printf "LABELS<> $GITHUB_ENV + printf "LABELS<> "$GITHUB_ENV" - name: Add Labels To Issue if: env.LABELS != '' - uses: actions-ecosystem/action-add-labels@v1 - with: - labels: | - Severity: ${{ env.SELECTED_SEVERITY }} - ${{ env.LABELS }} + env: + GH_TOKEN: ${{ github.token }} + ISSUE_NUMBER: ${{ github.event.issue.number }} + REPOSITORY: ${{ github.repository }} + run: | + jq -n \ + --arg severity "$SELECTED_SEVERITY" \ + --arg labels "$LABELS" \ + '{labels: (["Severity: " + $severity] + ($labels | split("\n") | map(select(length > 0))))}' \ + | gh api --method POST "repos/$REPOSITORY/issues/$ISSUE_NUMBER/labels" --input - - name: Handle Missing Label if: env.LABELS == '' diff --git a/.github/workflows/lock.yml b/.github/workflows/lock.yml index 33cd335..1cf87de 100644 --- a/.github/workflows/lock.yml +++ b/.github/workflows/lock.yml @@ -5,6 +5,8 @@ on: - cron: '0 0 * * *' workflow_dispatch: +permissions: {} + concurrency: group: ${{ github.workflow }} cancel-in-progress: false @@ -13,10 +15,13 @@ jobs: lock: name: Lock Inactive Threads runs-on: ubuntu-latest + permissions: + issues: write + pull-requests: write steps: - name: Lock Inactive Issues And Pull Requests - uses: dessant/lock-threads@v5 + uses: dessant/lock-threads@89ae32b08ed1a541efecbab17912962a5e38981c # v6.0.2 with: github-token: ${{ github.token }} - issue-lock-inactive-days: '2' - pr-lock-inactive-days: '2' + issue-inactive-days: '2' + pr-inactive-days: '2' diff --git a/.github/workflows/prettier.yml b/.github/workflows/prettier.yml index 93fb35a..78a374c 100644 --- a/.github/workflows/prettier.yml +++ b/.github/workflows/prettier.yml @@ -4,6 +4,9 @@ on: pull_request: branches: [master] +permissions: + contents: read + concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true @@ -15,19 +18,14 @@ jobs: steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false - name: Setup Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: - node-version: '20' - - - name: Install Prettier - run: | - rm package.json - rm package-lock.json - npm init -y - npm install prettier@3.2.5 + node-version: '24' - name: Check Code Formatting - run: npx prettier --check "./src/**/*.{ts,tsx,js,css}" + run: npx --yes prettier@3.2.5 --check "./src/**/*.{ts,tsx,js,css}" diff --git a/.github/workflows/publish-plugins.yml b/.github/workflows/publish-plugins.yml index 490bf2a..279c89b 100644 --- a/.github/workflows/publish-plugins.yml +++ b/.github/workflows/publish-plugins.yml @@ -10,6 +10,9 @@ on: - 'scripts/publish-plugins.sh' - '.github/workflows/publish-plugins.yml' +permissions: + contents: read + concurrency: group: ${{ github.workflow }} cancel-in-progress: true @@ -20,17 +23,17 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: token: ${{ secrets.REPO_SCOPED_TOKEN }} - name: Setup Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: - node-version: '20' + node-version: '24' - name: Install Dependencies - run: npm install --omit=dev --ignore-scripts + run: npm ci --omit=dev --ignore-scripts - name: Configure Git run: | diff --git a/.github/workflows/theme_auto_label.yml b/.github/workflows/theme_auto_label.yml index daf3203..a2cf74b 100644 --- a/.github/workflows/theme_auto_label.yml +++ b/.github/workflows/theme_auto_label.yml @@ -4,6 +4,9 @@ on: issues: types: [labeled] +permissions: + issues: write + concurrency: group: ${{ github.workflow }}-${{ github.event.issue.number }} cancel-in-progress: true diff --git a/.github/workflows/update-issue-template.yml b/.github/workflows/update-issue-template.yml index 7be4afb..421f6f2 100644 --- a/.github/workflows/update-issue-template.yml +++ b/.github/workflows/update-issue-template.yml @@ -26,20 +26,20 @@ jobs: github.event.workflow_run.event == 'push' steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: ref: master - name: Setup Node.js - uses: actions/setup-node@v4 + uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: - node-version: '20' + node-version: '24' - name: Generate Issue Template Options run: node ./.github/scripts/generate-issue-template-options.cjs - name: Create Or Update Pull Request - uses: peter-evans/create-pull-request@v7 + uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 with: commit-message: 'chore: Update Issue Template Plugin Options [skip ci]' branch: 'update-issue-template'