chore(ci): Harden Workflows And Pin Actions

This commit is contained in:
Rajarshee Chatterjee
2026-07-21 08:46:17 +05:30
parent 8d4d7f7a96
commit da78a3c3d8
6 changed files with 59 additions and 36 deletions
+28 -14
View File
@@ -6,6 +6,8 @@ on:
- opened
- edited
permissions: {}
concurrency:
group: ${{ github.workflow }}-${{ github.event.issue.number }}
cancel-in-progress: true
@@ -15,15 +17,22 @@ jobs:
name: Auto Label Issues
if: ${{ github.event.issue.body && contains(github.event.issue.body, '### Plugin') && contains(github.event.issue.labels.*.name, 'Bug') }}
runs-on: ubuntu-latest
permissions:
contents: read
issues: write
env:
ISSUE_BODY: ${{ github.event.issue.body }}
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Extract Severity From Issue Body
id: extract-severity
run: |
USER_SELECTED_SEVERITY=$(echo "${{ github.event.issue.body }}" | grep "### Severity" -A 2 | tail -n 1 | sed 's/[[:space:]]*$//')
USER_SELECTED_SEVERITY=$(printf '%s\n' "$ISSUE_BODY" | grep "### Severity" -A 2 | tail -n 1 | sed 's/[[:space:]]*$//')
SELECTED_SEVERITY=""
case "$USER_SELECTED_SEVERITY" in
@@ -34,26 +43,26 @@ jobs:
SELECTED_SEVERITY="Other"
;;
esac
echo "SELECTED_SEVERITY=$SELECTED_SEVERITY" >> $GITHUB_ENV
echo "SELECTED_SEVERITY=$SELECTED_SEVERITY" >> "$GITHUB_ENV"
- name: Extract Plugin From Issue Body
id: parse-issue
run: |
SELECTED_PLUGIN=$(echo "${{ github.event.issue.body }}" | awk '/### Plugin/ {f=1; next} f && NF {print; exit}' | sed 's/^[[:space:]]*//;s/[[:space:]]*$//')
SELECTED_PLUGIN=$(printf '%s\n' "$ISSUE_BODY" | awk '/### Plugin/ {f=1; next} f && NF {print; exit}' | sed 's/^[[:space:]]*//;s/[[:space:]]*$//')
echo "SELECTED_PLUGIN=$SELECTED_PLUGIN" >> $GITHUB_ENV
echo "SELECTED_PLUGIN=$SELECTED_PLUGIN" >> "$GITHUB_ENV"
- name: Extract Language From Issue Body
id: extract-language
run: |
SELECTED_LANGUAGE=$(echo "${{ github.event.issue.body }}" | awk '/### Language/ {f=1; next} f && NF {print; exit}' | sed 's/^[[:space:]]*//;s/[[:space:]]*$//')
SELECTED_LANGUAGE=$(printf '%s\n' "$ISSUE_BODY" | awk '/### Language/ {f=1; next} f && NF {print; exit}' | sed 's/^[[:space:]]*//;s/[[:space:]]*$//')
echo "SELECTED_LANGUAGE=$SELECTED_LANGUAGE" >> $GITHUB_ENV
echo "SELECTED_LANGUAGE=$SELECTED_LANGUAGE" >> "$GITHUB_ENV"
- name: Determine Corresponding Label
id: determine-label
run: |
LABELS="$( jq --arg keys "${{ env.SELECTED_PLUGIN }}" '. as $data | $keys | split(", ") as $keyList | $keyList[] | . as $key | if $data[$key] != null then "\($key)[\($data[$key])]" else empty end' ./.github/scripts/keys.json | sed 's/"//g' | sed 's/^[^:]*: //' )"
LABELS="$(jq --arg keys "$SELECTED_PLUGIN" '. as $data | $keys | split(", ") as $keyList | $keyList[] | . as $key | if $data[$key] != null then "\($key)[\($data[$key])]" else empty end' ./.github/scripts/keys.json | sed 's/"//g' | sed 's/^[^:]*: //')"
# Add "Plugin: " in front of each label
LABELS_WITH_PREFIX="$(echo "$LABELS" | sed 's/^/Plugin: /')"
@@ -65,15 +74,20 @@ jobs:
fi
# Save to GitHub environment
printf "LABELS<<EOF\n%s\nEOF\n" "$FINAL_LABELS" >> $GITHUB_ENV
printf "LABELS<<EOF\n%s\nEOF\n" "$FINAL_LABELS" >> "$GITHUB_ENV"
- name: Add Labels To Issue
if: env.LABELS != ''
uses: actions-ecosystem/action-add-labels@v1
with:
labels: |
Severity: ${{ env.SELECTED_SEVERITY }}
${{ env.LABELS }}
env:
GH_TOKEN: ${{ github.token }}
ISSUE_NUMBER: ${{ github.event.issue.number }}
REPOSITORY: ${{ github.repository }}
run: |
jq -n \
--arg severity "$SELECTED_SEVERITY" \
--arg labels "$LABELS" \
'{labels: (["Severity: " + $severity] + ($labels | split("\n") | map(select(length > 0))))}' \
| gh api --method POST "repos/$REPOSITORY/issues/$ISSUE_NUMBER/labels" --input -
- name: Handle Missing Label
if: env.LABELS == ''
+8 -3
View File
@@ -5,6 +5,8 @@ on:
- cron: '0 0 * * *'
workflow_dispatch:
permissions: {}
concurrency:
group: ${{ github.workflow }}
cancel-in-progress: false
@@ -13,10 +15,13 @@ jobs:
lock:
name: Lock Inactive Threads
runs-on: ubuntu-latest
permissions:
issues: write
pull-requests: write
steps:
- name: Lock Inactive Issues And Pull Requests
uses: dessant/lock-threads@v5
uses: dessant/lock-threads@89ae32b08ed1a541efecbab17912962a5e38981c # v6.0.2
with:
github-token: ${{ github.token }}
issue-lock-inactive-days: '2'
pr-lock-inactive-days: '2'
issue-inactive-days: '2'
pr-inactive-days: '2'
+9 -11
View File
@@ -4,6 +4,9 @@ on:
pull_request:
branches: [master]
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
@@ -15,19 +18,14 @@ jobs:
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Setup Node.js
uses: actions/setup-node@v4
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '20'
- name: Install Prettier
run: |
rm package.json
rm package-lock.json
npm init -y
npm install prettier@3.2.5
node-version: '24'
- name: Check Code Formatting
run: npx prettier --check "./src/**/*.{ts,tsx,js,css}"
run: npx --yes prettier@3.2.5 --check "./src/**/*.{ts,tsx,js,css}"
+7 -4
View File
@@ -10,6 +10,9 @@ on:
- 'scripts/publish-plugins.sh'
- '.github/workflows/publish-plugins.yml'
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}
cancel-in-progress: true
@@ -20,17 +23,17 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
token: ${{ secrets.REPO_SCOPED_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '20'
node-version: '24'
- name: Install Dependencies
run: npm install --omit=dev --ignore-scripts
run: npm ci --omit=dev --ignore-scripts
- name: Configure Git
run: |
+3
View File
@@ -4,6 +4,9 @@ on:
issues:
types: [labeled]
permissions:
issues: write
concurrency:
group: ${{ github.workflow }}-${{ github.event.issue.number }}
cancel-in-progress: true
+4 -4
View File
@@ -26,20 +26,20 @@ jobs:
github.event.workflow_run.event == 'push'
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
ref: master
- name: Setup Node.js
uses: actions/setup-node@v4
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '20'
node-version: '24'
- name: Generate Issue Template Options
run: node ./.github/scripts/generate-issue-template-options.cjs
- name: Create Or Update Pull Request
uses: peter-evans/create-pull-request@v7
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
commit-message: 'chore: Update Issue Template Plugin Options [skip ci]'
branch: 'update-issue-template'