Skip to content

chore: upgrade workflows and update dependencies - #214

Open
borisonekenobi wants to merge 27 commits into
angular-schule:mainfrom
borisonekenobi:main
Open

borisonekenobi wants to merge 27 commits into
angular-schule:mainfrom
borisonekenobi:main

Conversation

@borisonekenobi

Copy link
Copy Markdown

This pull request introduces several improvements to CI/CD automation, dependency management, and code quality. The main changes include adding Dependabot configuration for automated dependency updates, upgrading GitHub Actions to the latest major versions, updating development dependencies to their latest versions, and making minor code and test improvements for better type safety and maintainability.

CI/CD and Dependency Management Improvements:

  • Added a .github/dependabot.yml file to enable automated dependency updates for both npm and GitHub Actions, scheduled weekly.
  • Upgraded GitHub Actions used in workflow files (main.yml, npm-publish.yml) to the latest major versions (actions/checkout@v7, actions/setup-node@v7, actions/upload-artifact@v7, actions/download-artifact@v8). [1] [2] [3] [4] [5]

Development Dependency Updates:

  • Updated several development dependencies in src/package.json to their latest major versions, including @angular-devkit/*, @types/node, json-schema-to-typescript, rimraf, typescript, and vitest.
  • Updated the TypeScript configuration in src/tsconfig.json to use module: node16 and moduleResolution: node16 for better compatibility with newer Node.js and TypeScript versions.

Testing and Type Improvements:

  • Improved the mock implementation for gh-pages/lib/git in engine.gh-pages-integration.spec.ts to use a class-based mock, increasing test clarity and maintainability.
  • Updated a test in engine.spec.ts to check for the correct repository path (borisonekenobi/angular-cli-ghpages).
  • Improved type safety for the beforeAdd hook in PublishOptions by specifying the correct GhPagesGit type and adding the import in src/interfaces.ts. [1] [2]
  • Added a type assertion in src/ng-add.ts for better type safety when selecting the default project.

borisonekenobi and others added 25 commits October 4, 2026 12:02
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v8)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [json-schema-to-typescript](https://github.com/bcherny/json-schema-to-typescript) from 13.1.2 to 16.0.0.
- [Changelog](https://github.com/bcherny/json-schema-to-typescript/blob/master/CHANGELOG.md)
- [Commits](https://github.com/bcherny/json-schema-to-typescript/commits)

---
updated-dependencies:
- dependency-name: json-schema-to-typescript
  dependency-version: 16.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@angular-devkit/schematics](https://github.com/angular/angular-cli) from 18.0.7 to 22.2.1.
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@18.0.7...v22.2.1)

---
updated-dependencies:
- dependency-name: "@angular-devkit/schematics"
  dependency-version: 22.2.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rimraf](https://github.com/isaacs/rimraf) from 5.0.10 to 6.1.3.
- [Changelog](https://github.com/isaacs/rimraf/blob/main/CHANGELOG.md)
- [Commits](isaacs/rimraf@v5.0.10...v6.1.3)

---
updated-dependencies:
- dependency-name: rimraf
  dependency-version: 6.1.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 3.2.6 to 5.0.3.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.26.0 to 6.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.26.0...v6.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.7.3.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.2.0...v10.7.3)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.7.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.8.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.2...v3.1.8)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.12.24 to 4.13.13.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.24...v4.13.13)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.13
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the angular group with 2 updates in the /src directory: [@angular-devkit/architect](https://github.com/angular/angular-cli) and [@angular-devkit/core](https://github.com/angular/angular-cli).


Updates `@angular-devkit/architect` from 0.1800.7 to 0.2202.1
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular-cli/commits)

Updates `@angular-devkit/core` from 18.0.7 to 22.2.1
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@18.0.7...v22.2.1)

---
updated-dependencies:
- dependency-name: "@angular-devkit/architect"
  dependency-version: 0.2202.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: angular
- dependency-name: "@angular-devkit/core"
  dependency-version: 22.2.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: angular
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps  and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together.

Updates `brace-expansion` from 5.0.6 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.12)

Updates `brace-expansion` from 1.1.15 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.12)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.15.2 to 6.16.0.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.15.2...v6.16.0)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Removes [pacote](https://github.com/npm/pacote). It's no longer used after updating ancestor dependency [@angular/cli](https://github.com/angular/angular-cli). These dependencies need to be updated together.


Removes `pacote`

Updates `@angular/cli` from 22.0.0 to 22.2.1
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@v22.0.0...v22.2.1)

---
updated-dependencies:
- dependency-name: "@angular/cli"
  dependency-version: 22.2.1
  dependency-type: indirect
- dependency-name: pacote
  dependency-version:
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.2.2 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.2.2...v7.0.2)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 24.13.1 to 26.6.3.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI balanced review requested due to automatic review settings October 4, 2026 18:16

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Comment thread .github/dependabot.yml Outdated
interval: "weekly"
day: "sunday"
time: "09:00"
timezone: "America/Toronto"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since this project is Europe-based, we should set this to Europe/Berlin

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same below

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed

Comment thread src/tsconfig.json
"module": "commonjs",
"moduleResolution": "node",
"module": "node16",
"moduleResolution": "node16",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the reason to set this to "node16" specifically?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Typescript v6 removes node as an available moduleResolution, and the suggested fix by GitHub Copilot was node16, other than that, no opinion on specific module or moduleResolution

Comment thread .github/dependabot.yml Outdated
- package-ecosystem: "npm"
directory: "/src/"
schedule:
interval: "weekly"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We release this tool in a much larger interval, so I suggest monthly dep updates. Everything shorter than this is highly annoying for maintainers.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Resolve the Angular 18 compatibility and Node engine requirement inconsistencies in src/package.json.

Review effort: Lite
Findings: None

@fmalcher

fmalcher commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Thanks for the PR, @borisonekenobi 😊
Apart from my smaller comments, LGTM at first quick sight.
I have set up Dependabot in another project too, and like it 👍

@fmalcher
fmalcher requested a review from JohannesHoppe October 4, 2026 18:32
@JohannesHoppe

JohannesHoppe commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Hi @borisonekenobi, thank you so much for this PR and for taking the time to work through the review feedback! 🙏

The code changes are great: the class-based MockGit and the proper GhPagesGit type for beforeAdd are real improvements, and I'd love to merge them. The TypeScript upgrade and the upgraded GitHub Actions are fine with me too.

Dependabot is where I have a real stomachache, though. Supply-chain attacks have become a huge problem in the npm ecosystem, and according to GitHub, 66,408 repositories depend on angular-cli-ghpages. Every dependency change I ship ends up in all of those build pipelines, and I take that responsibility seriously. That's why I've deliberately cut down the dependency footprint over time. I even inlined and slimmed down former dependencies so there's less code from third parties in the chain.

My approach: outdated dependencies on their own aren't a problem. If there's a security finding, it gets handled right away. Otherwise I update dependencies by hand before each release, alongside Angular/AngularFire, and test everything together. A bot that continuously bumps versions works against that. The devDependencies are also intentionally pinned to the lowest supported Angular version (18), so the build always runs against the minimum the package claims to support (see docs/README_contributors.md).

So would you mind trimming the PR down to the code changes? Concretely:

  • remove .github/dependabot.yml
  • drop the remaining Dependabot bump commits for the other devDependencies (keep the TypeScript bump in package.json and the GitHub Actions upgrades in the workflow files)
  • drop the changes to package-lock.json, I'll regenerate it myself

That leaves the MockGit refactoring, the beforeAdd type, the TypeScript upgrade (including the tsconfig.json change and the as string cast in ng-add.ts) and the GitHub Actions upgrades, which I'm happy to merge. I'll do the next round of dependency updates (Vitest etc.) myself before the next release.

Thanks again, contributions like this are really appreciated! 😊

@JohannesHoppe JohannesHoppe left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

see comment

@borisonekenobi

Copy link
Copy Markdown
Author

Thanks for the detailed feedback. I understand the concern, especially given how many downstream projects use the package and the responsibility that comes with changing its dependency chain.

I can trim the PR as requested, but I wanted to point out a few details first. Not all of the dependency updates in this PR are just version bumps. Some of them resolve security vulnerabilities that Dependabot found. The updates reduce the reported vulnerabilities from 83 to 1. (link to resolved vulnerabilities) The remaining vulnerability hasn't been resolved in the upstream packages yet, so there is currently no update that can address it (and, unfortunately, that vulnerability is also what originally prompted me to start this PR).

With that in mind, I wanted to suggest a slightly different approach:

  1. Keep the dependency updates that actually resolve the reported vulnerabilities. These differ from routine dependency updates because they directly address known security issues.

  2. Configure Dependabot to only create PRs for security updates. This would let you handle security findings immediately while continuing to update other dependencies manually before releases. It would also avoid the continuous stream of routine version bumps that you are concerned about.

  3. If you are open to it, keep the Dependabot configuration for the GitHub Actions. These updates do not affect the dependency tree of downstream repositories, and they are generally more isolated from the package itself. They also rarely introduce breaking changes to the workflow.

If you would still prefer to remove Dependabot completely, that is fine too. I want to flag this before we remove everything, as we may be able to keep the security benefits without continuous dependency updates.

Either way, I can make the changes and get the PR into a state you are comfortable merging.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants