From a57582532016cde529bc36a7dffcf9341cb1cebd Mon Sep 17 00:00:00 2001 From: Lukas Geiger Date: Thu, 1 Oct 2026 15:48:12 +0200 Subject: [PATCH 1/2] fix(ci): repair first-interaction v3 input names and pin action --- .github/workflows/welcome.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/welcome.yml b/.github/workflows/welcome.yml index dd9032e..a9a5666 100644 --- a/.github/workflows/welcome.yml +++ b/.github/workflows/welcome.yml @@ -20,8 +20,8 @@ jobs: timeout-minutes: 5 steps: - name: Welcome First Interaction - uses: actions/first-interaction@v3 + uses: actions/first-interaction@1c4688942c71f71d4f5502a26ea67c331730fa4d # v3 with: - repo-token: ${{ secrets.GITHUB_TOKEN }} - issue-message: "Welcome to DokuZen! Thank you for opening an issue. Our team reviews issues promptly." - pr-message: "Welcome to DokuZen! Thank you for submitting a pull request. We will review your contribution shortly." + repo_token: ${{ secrets.GITHUB_TOKEN }} + issue_message: "Welcome to DokuZen! Thank you for opening an issue. Our team reviews issues promptly." + pr_message: "Welcome to DokuZen! Thank you for submitting a pull request. We will review your contribution shortly." From e5af8efe52375d036f8adb07ce580379c69af9db Mon Sep 17 00:00:00 2001 From: Lukas Geiger Date: Thu, 1 Oct 2026 15:51:03 +0200 Subject: [PATCH 2/2] test(ci): enforce pinned welcome action and valid input names --- tests/test_metadata.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/tests/test_metadata.py b/tests/test_metadata.py index 2fba332..0e2100e 100644 --- a/tests/test_metadata.py +++ b/tests/test_metadata.py @@ -404,7 +404,11 @@ def test_ci_lifecycle_and_hardening_workflows(): welcome_path = workflows_dir / "welcome.yml" assert welcome_path.exists(), "welcome.yml must exist" w_content = welcome_path.read_text(encoding="utf-8") - assert "actions/first-interaction@v3" in w_content + assert re.search(r"^\s+uses: actions/first-interaction@[0-9a-f]{40}(?:\s+#.*)?$", w_content, re.MULTILINE) + welcome_inputs = set(re.findall( + r"^\s+(repo[_-]token|issue[_-]message|pr[_-]message):", w_content, re.MULTILINE + )) + assert welcome_inputs == {"repo_token", "issue_message", "pr_message"} assert "timeout-minutes: 5" in w_content assert "cancel-in-progress: true" in w_content assert "issues: write" in w_content