Skip to content

chore: pin github actions to commit sha, update pnpm#2761

Merged
kettanaito merged 5 commits into
mainfrom
chore/pin-actions
Jul 7, 2026
Merged

chore: pin github actions to commit sha, update pnpm#2761
kettanaito merged 5 commits into
mainfrom
chore/pin-actions

Conversation

@kettanaito

@kettanaito kettanaito commented Jul 7, 2026

Copy link
Copy Markdown
Member
  • Also uses Node.js 20 correctly for relevant jobs.
  • Downgrades to undici@7 since the latest version doesn't support Node.js 20.

@socket-security

socket-security Bot commented Jul 7, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @emnapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/vitest@4.1.10npm/knip@6.25.0npm/@emnapi/runtime@1.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/runtime@1.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @mswjs/interceptors is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/@mswjs/interceptors@0.41.9

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@mswjs/interceptors@0.41.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm es-abstract is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/babel-minify@0.5.2npm/es-abstract@1.24.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-abstract@1.24.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm rrweb-cssom is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/jsdom@25.0.1npm/rrweb-cssom@0.8.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/rrweb-cssom@0.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm webpack is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/webpack@5.108.4

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webpack@5.108.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@coderabbitai

coderabbitai Bot commented Jul 7, 2026

Copy link
Copy Markdown

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 41cccbb2-6950-4ec9-a2bc-a34aef7ee9c8

📥 Commits

Reviewing files that changed from the base of the PR and between 8a19d54 and 8b251d7.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (8)
  • .github/workflows/ci.yml
  • .github/workflows/compat.yml
  • .github/workflows/release-preview.yml
  • .github/workflows/release.yml
  • .github/workflows/smoke-test.yml
  • .github/workflows/typescript-nightly.yml
  • package.json
  • pnpm-workspace.yaml
 ________________________________________________
< Love the optimism of `// should never happen`. >
 ------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/pin-actions

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

coderabbitai Bot commented Jul 7, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: b8835a90-c828-4521-94c0-5e20d2c80230

📥 Commits

Reviewing files that changed from the base of the PR and between 77e6dc9 and 467104b.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .github/workflows/ci.yml
  • package.json
  • test/node/ws-api/ws.upgrade.test.ts
  • test/support/environments/vitest-environment-node-websocket.ts
✅ Files skipped from review due to trivial changes (1)
  • test/node/ws-api/ws.upgrade.test.ts

📝 Walkthrough

Walkthrough

Multiple GitHub Actions workflows now pin third-party actions to commit SHAs, several ci.yml jobs change Node version and build dependencies, smoke-test.yml updates pnpm, and the WebSocket upgrade test uses a dedicated Vitest environment with a conditional WebSocket setup.

Changes

CI workflow action pinning

Layer / File(s) Summary
Build jobs and cache pinning
.github/workflows/ci.yml
build-20 and build-22 pin checkout and setup-node, keep pnpm/action-setup on version 9.15.0, and update their cache steps to pinned actions/cache references.
Test job dependencies and artifact upload
.github/workflows/ci.yml
test-unit and test-browser switch their build dependency to build-22, pin checkout/setup-node/cache, and test-browser pins the Playwright artifact upload step.
Node-specific test jobs
.github/workflows/ci.yml
test-node-20, test-node-22, test-e2e, and test-native pin checkout/setup-node/cache, and test-e2e and test-native change their Node version to 20.

Other workflow action pinning

Layer / File(s) Summary
Workflow action pins
.github/workflows/compat.yml, .github/workflows/release-preview.yml, .github/workflows/release.yml, .github/workflows/typescript-nightly.yml
compat.yml, release-preview.yml, release.yml, and typescript-nightly.yml replace floating checkout and setup-node tags with pinned commit SHAs; release.yml also pins pnpm/action-setup, upload-artifact, and download-artifact.
Smoke test setup
.github/workflows/smoke-test.yml
smoke-test.yml pins checkout and setup-node and updates the pnpm version to 11.5.2.

WebSocket test runtime

Layer / File(s) Summary
WebSocket test runtime
test/node/ws-api/ws.upgrade.test.ts, test/support/environments/vitest-environment-node-websocket.ts, package.json
ws.upgrade.test.ts switches to the node-websocket environment, the environment only assigns globalThis.WebSocket when missing, and package.json updates the undici devDependency version.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • mswjs/msw#2719: Both PRs modify test/support/environments/vitest-environment-node-websocket.ts.
  • mswjs/msw#2732: Both PRs touch the WebSocket upgrade test path and the node-websocket Vitest environment.
  • mswjs/msw#2747: Both PRs update GitHub workflow YAMLs to pin actions to specific commit SHAs.

Poem

I hopped through CI with a careful grin,
Pinned every action where tags had been.
A WebSocket warren, snug and bright,
Now only wakes when globals aren’t in sight.
Hop, hop! 🐇

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title matches the main changes: pinning GitHub Actions and updating pnpm.
Description check ✅ Passed The description is related to the PR because it mentions the Node.js 20 job updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/pin-actions

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
.github/workflows/ci.yml (1)

18-29: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Verified SHA pins for actions/checkout, actions/cache, and actions/setup-node.

Spot-checked via GitHub: actions/checkout@9c091bb2... = v7.0.0, actions/cache@55cc8345... = the v6.1.0 bump, actions/setup-node@48b55a01... = v6.4.0. These match the intended tags.

However, none of the pins in this file include an inline # vX.Y.Z comment, which is the widely-used convention for pinned actions (readability + easier future audits/bumps). Consider adding version comments to every pinned uses: line, e.g.:

♻️ Example
-        uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
+        uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

Also applies to: 53-61, 75-75, 88-101, 123-136, 158-171, 193-203, 217-230, 248-248, 259-272

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 18 - 29, Add inline version comments
to every pinned GitHub Actions `uses:` entry in the workflow so the referenced
action version is obvious at a glance. Update the existing pinned steps in the
CI workflow (for example the `actions/checkout`, `pnpm/action-setup`, and
`actions/setup-node` steps) to include their corresponding `# vX.Y.Z` tags, and
apply the same convention to the other pinned action blocks referenced in this
file.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 18-29: Add inline version comments to every pinned GitHub Actions
`uses:` entry in the workflow so the referenced action version is obvious at a
glance. Update the existing pinned steps in the CI workflow (for example the
`actions/checkout`, `pnpm/action-setup`, and `actions/setup-node` steps) to
include their corresponding `# vX.Y.Z` tags, and apply the same convention to
the other pinned action blocks referenced in this file.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 41cccbb2-6950-4ec9-a2bc-a34aef7ee9c8

📥 Commits

Reviewing files that changed from the base of the PR and between 8a19d54 and 8b251d7.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (8)
  • .github/workflows/ci.yml
  • .github/workflows/compat.yml
  • .github/workflows/release-preview.yml
  • .github/workflows/release.yml
  • .github/workflows/smoke-test.yml
  • .github/workflows/typescript-nightly.yml
  • package.json
  • pnpm-workspace.yaml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/ci.yml (1)

18-29: 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win

These SHA pins jump major versionscheckout v7, setup-node v6, cache v6, and upload-artifact v7, so this is more than a straight pin of the current v4 line-up. Split the upgrade from the pinning change or call it out explicitly.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 18 - 29, The workflow currently pins
GitHub Actions to SHAs that jump major versions, so the change is not just a
simple pin of the existing releases. Update the CI workflow entries for
actions/checkout and actions/setup-node to either stay on the current major line
or split this into a separate upgrade PR, and make the version bump explicit if
you keep the new SHAs.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/ci.yml:
- Around line 18-29: The workflow currently pins GitHub Actions to SHAs that
jump major versions, so the change is not just a simple pin of the existing
releases. Update the CI workflow entries for actions/checkout and
actions/setup-node to either stay on the current major line or split this into a
separate upgrade PR, and make the version bump explicit if you keep the new
SHAs.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: af9070f7-5451-4ae5-ab05-bc65dd8fed37

📥 Commits

Reviewing files that changed from the base of the PR and between 8b251d7 and 77e6dc9.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (6)
  • .github/workflows/ci.yml
  • .github/workflows/compat.yml
  • .github/workflows/release-preview.yml
  • .github/workflows/release.yml
  • .github/workflows/smoke-test.yml
  • .github/workflows/typescript-nightly.yml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/smoke-test.yml

@pkg-pr-new

pkg-pr-new Bot commented Jul 7, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/msw@2761

commit: 77e6dc9

@kettanaito
kettanaito merged commit ff6836b into main Jul 7, 2026
28 of 30 checks passed
@kettanaito
kettanaito deleted the chore/pin-actions branch July 7, 2026 11:17
@kettanaito

Copy link
Copy Markdown
Member Author

Released: v2.14.7 🎉

This has been released in v2.14.7.

Get these changes by running the following command:

npm i msw@latest

Predictable release automation by Release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant