chore(ci): upgrade actions - #165
Merged
Merged
Conversation
|
Coverage after merging chore/ci/upgrade-actions into main will be
Coverage Report
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Contributor
There was a problem hiding this comment.
Pull request overview
Updates this repo’s GitHub Actions workflow dependencies by bumping the pinned SHAs for commonly used actions (checkout, Bun setup, and sticky PR comment), keeping CI/CD workflows aligned with the project’s “SHA-pin actions” security posture.
Changes:
- Upgrade
actions/checkoutpins across workflows to v7.0.1 (SHA-pinned). - Upgrade
oven-sh/setup-bunpins across workflows to v2.2.0 (SHA-pinned). - Upgrade
marocchino/sticky-pull-request-commentusage/docs to v3.0.5 (SHA-pinned).
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/responsive.yaml | Bump actions/checkout and setup-bun pins used by the responsive check. |
| .github/workflows/lighthouse.yaml | Bump checkout/setup-bun pins and update sticky PR comment action pin. |
| .github/workflows/docs.yaml | Bump checkout/setup-bun pins in both docs deploy and snapshot jobs. |
| .github/workflows/ci.yaml | Bump checkout/setup-bun pins in CI jobs. |
| .github/workflows/cd.yaml | Bump checkout/setup-bun pins in CD build job (note: still has unpinned actions/* elsewhere). |
| .github/workflows/a11y.yaml | Bump checkout/setup-bun pins for the accessibility audit workflow. |
| .github/skills/github-actions.md | Update the documented sticky PR comment action pin to v3.0.5. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🔦 Lighthouse Report
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.