Skip to content

ci: re-pin the cached setup-node action - #122

Merged
felipesauer merged 1 commit into
mainfrom
ci/repin-setup-node
Aug 26, 2026
Merged

felipesauer merged 1 commit into
mainfrom
ci/repin-setup-node

Conversation

@felipesauer

Copy link
Copy Markdown
Owner

The last parity gap between this repo and safeaccess-identum.

.github/actions/setup-node-cached is the composite js-ci actually calls,
and it was still pinned to:

Action Was Now
actions/setup-node 53b8394… (2026-03-02, v6.x) 8207627… = v7.0.0
actions/cache cdf6c1f… = v5.0.3 (January) 55cc834… (June)

Dependabot updates .github/workflows, not .github/actions, so every JS
job here has been running a March build of setup-node without anything
flagging it. #118 fixed the coverage composite; this one closes the pair.

Also removes the mention of packages/cli from the eslint.config.js header
— no such package exists here.

After this, the only intentional differences left between the two repos are
the mutation thresholds (90/100 here, 85 there) and the package contents.

This composite is the one js-ci actually uses, and it was still pinned to a
setup-node build from March (v6.x) and actions/cache v5.0.3 — while the
workflows elsewhere had moved on. Dependabot updates .github/workflows, not
.github/actions, so nothing corrected it.

Now on the same SHAs safeaccess-identum uses: setup-node v7.0.0 and the June
build of actions/cache.

Also drops the reference to packages/cli from the eslint config comment —
that package does not exist in this repo.
@codecov

codecov Bot commented Aug 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@felipesauer
felipesauer merged commit 681c260 into main Aug 26, 2026
4 checks passed
@felipesauer
felipesauer deleted the ci/repin-setup-node branch August 26, 2026 17:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant