Repository navigation
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
chore(ci-governance): adopt Node profile
* chore(ci-governance): synchronize Node profile Governance-Provenance: hmac-sha256:0837805e11b99a61122d875508937baaf8f6e7ea3020166fd7d18275ddf05021 * chore(ci-governance): synchronize Node profile Governance-Provenance: hmac-sha256:9f99e6a9dcda0869e8a2b16e662ab3934595ca748bc2a31590f6fe405a176c10 * chore(ci-governance): synchronize Node profile Governance-Provenance: hmac-sha256:6349bde86c5f9ca562cdc9e04317b9a0ed7997de24d1e0a58023f15bb0840ea7 --------- Co-authored-by: inditextechci-sync[bot] <312492039+inditextechci-sync[bot]@users.noreply.github.com>
Governance-Provenance: hmac-sha256:a1b6e524ca9f6ce4c32b3a48b2236f856760e1ffb52ab1bf1040104860858f6c Co-authored-by: inditextechci-sync[bot] <312492039+inditextechci-sync[bot]@users.noreply.github.com>
* chore(ci-governance): synchronize Node profile Governance-Provenance: hmac-sha256:438b9a2ed034fe83792f50e2f24b554dc25b549c0dccd10f000b52b7b0dc9b18 * chore(ci-governance): synchronize Node profile Governance-Provenance: hmac-sha256:e52a0fa7ce2702b06cd4f63f609b437a645287cc40fd2a5d71256de0739ccf4b --------- Co-authored-by: inditextechci-sync[bot] <312492039+inditextechci-sync[bot]@users.noreply.github.com>
* docs: remove empty Development section in CONTRIBUTING * docs: fix 'recommend to use' -> 'recommend using' in CONTRIBUTING
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
sync-develop
Governance-Provenance: hmac-sha256:2a1a3c9bcc9eed2eb78db0630a7376b920c120c3a50ff7caf64cb499c1b9b6f8
Governance-Provenance: hmac-sha256:27a539fd921b3dc485736c72e0b990f4e80e9f9eadd0a39b53c0dc1078cf0511
Governance-Provenance: hmac-sha256:7c5063e572e2a745640531909b4f8037bc5a8463cc324f907f3aa300aef7a2b2
chore(ci-governance): synchronize Node profile
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.11 to 5.0.1. - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-version: 5.0.1 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [swagger-ui-react](https://github.com/swagger-api/swagger-ui) from 5.32.14 to 5.33.0. - [Release notes](https://github.com/swagger-api/swagger-ui/releases) - [Commits](swagger-api/swagger-ui@v5.32.14...v5.33.0) --- updated-dependencies: - dependency-name: swagger-ui-react dependency-version: 5.33.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [prettier](https://github.com/prettier/prettier) from 3.9.6 to 3.9.8. - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.9.6...3.9.8) --- updated-dependencies: - dependency-name: prettier dependency-version: 3.9.8 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
* chore(ci-governance): synchronize Node profile Governance-Provenance: hmac-sha256:cea719fa0a94c0a129876ddf39623a83de6718bd0610c8ee1bb52e9f830799b5 * chore(ci-governance): synchronize Node profile Governance-Provenance: hmac-sha256:a0d13af33b94dac8034b6e3da720b99fd295355064354e48808ff7425af9f79d * chore(ci-governance): synchronize Node profile Governance-Provenance: hmac-sha256:27c98b36663866b3da69897d84ed0996e4b697df4291d336f20ff3f0c4030a13 --------- Co-authored-by: inditextechci-sync[bot] <312492039+inditextechci-sync[bot]@users.noreply.github.com> Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [undici](https://github.com/nodejs/undici) from 7.29.0 to 7.30.0. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.29.0...v7.30.0) --- updated-dependencies: - dependency-name: undici dependency-version: 7.30.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.14 to 3.4.16. - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.14...3.4.16) --- updated-dependencies: - dependency-name: dompurify dependency-version: 3.4.16 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
…rsions (#42) Resolves the 8 open Dependabot alerts: - undici 7.29.0 -> 7.30.0 (transitive of jsdom, dev, root lockfile): GHSA-3wwx-pv8p-q78v, GHSA-pmjh-fq2x-6v4x, GHSA-r53p-7pc4-xj5r - dompurify 3.4.14 -> 3.4.16 (root dev + example runtime, both via swagger-ui-react): GHSA-p98j-92pf-mc4p - brace-expansion 1.1.18 -> 1.21, 5.0.9 -> 5.0.12 (root, dev): GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p, GHSA-q2hr-2g5m-vwhr npm audit reports 0 vulnerabilities in both lockfiles; npm run verify (lint, prettier, 21 vitest tests, build) passes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2. - [Release notes](https://github.com/7rulnik/source-map-js/releases) - [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md) - [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2) --- updated-dependencies: - dependency-name: source-map-js dependency-version: 1.2.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.18 to 1.1.21. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 1.1.21 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Comment on lines
+661
to
+741
| run: | | ||
| set -euo pipefail | ||
|
|
||
| case ",$RELEASE_LABELS," in | ||
| *",release-type/major,"*) release_bump="major" ;; | ||
| *",release-type/minor,"*) release_bump="minor" ;; | ||
| *",release-type/hotfix,"*|*",release-type/multi-hotfix,"*|*",release-type/patch,"*) | ||
| release_bump="patch" | ||
| ;; | ||
| *) | ||
| if [[ "$DEVELOPMENT_FLOW" == "trunk-based-development" ]]; then | ||
| release_bump="minor" | ||
| else | ||
| echo "::error title=Missing release type::git-flow releases require a release-type label." | ||
| exit 1 | ||
| fi | ||
| ;; | ||
| esac | ||
| export RELEASE_BUMP="$release_bump" | ||
|
|
||
| git tag | sort > "$RUNNER_TEMP/tags-before.txt" | ||
|
|
||
| case "${PACKAGE_MANAGER:-npm}" in | ||
| npm) npm run release:prepare ;; | ||
| pnpm) corepack enable; pnpm run release:prepare ;; | ||
| *) echo "::error title=Invalid package manager::PACKAGE_MANAGER must be npm or pnpm."; exit 1 ;; | ||
| esac | ||
|
|
||
| git tag | sort > "$RUNNER_TEMP/tags-after.txt" | ||
| new_tags=() | ||
| while IFS= read -r tag; do | ||
| new_tags+=("$tag") | ||
| done < <(comm -13 "$RUNNER_TEMP/tags-before.txt" "$RUNNER_TEMP/tags-after.txt") | ||
| if [[ ${#new_tags[@]} -eq 0 ]]; then | ||
| echo "::error title=No release cut::release:prepare produced no new tags." | ||
| exit 1 | ||
| fi | ||
|
|
||
| records_file="$RUNNER_TEMP/node-release-records.jsonl" | ||
| : > "$records_file" | ||
| for tag in "${new_tags[@]}"; do | ||
| tag_target="$(git rev-parse "${tag}^{commit}")" | ||
| if [[ "$tag" =~ ([0-9]+\.[0-9]+\.[0-9]+([-+.][0-9A-Za-z.-]+)?)$ ]]; then | ||
| version="${BASH_REMATCH[1]}" | ||
| else | ||
| version="$tag" | ||
| fi | ||
| jq -cn \ | ||
| --arg tag "$tag" \ | ||
| --arg tag_target "$tag_target" \ | ||
| --arg version "$version" \ | ||
| --arg bump "$release_bump" \ | ||
| '{packages: [], version: $version, tag: $tag, tag_target: $tag_target, next_dev: "", release_bump: $bump}' \ | ||
| >> "$records_file" | ||
| done | ||
| releases="$(jq -cs . "$records_file")" | ||
| primary_version="$(jq -r '.[0].version' <<< "$releases")" | ||
|
|
||
| changelog_pending="false" | ||
| if [[ -f CHANGELOG.md ]] \ | ||
| && awk '/^## \[?[Uu]nreleased\]?/{f=1;next} /^## /{f=0} f && NF {print; exit}' CHANGELOG.md | grep -q .; then | ||
| changelog_pending="true" | ||
| fi | ||
|
|
||
| echo "RELEASE_BUMP=$release_bump" >> "$GITHUB_ENV" | ||
| echo "RELEASE_VERSION=$primary_version" >> "$GITHUB_ENV" | ||
| # CHANGELOG links must name real tags: independent workspaces tag | ||
| # <member>-<version>, so the prefix is the primary tag minus its | ||
| # version (empty for single and locked-step releases). | ||
| primary_tag="$(jq -r '.[0].tag' <<< "$releases")" | ||
| echo "CHANGELOG_TAG_PREFIX=${primary_tag%"$primary_version"}" >> "$GITHUB_ENV" | ||
|
|
||
| { | ||
| echo "expected_ref=refs/heads/$BASELINE_BRANCH" | ||
| echo "source_commit=$RELEASE_SOURCE_COMMIT" | ||
| echo "primary_version=$primary_version" | ||
| echo "changelog_pending=$changelog_pending" | ||
| echo "releases_intermediate<<EOF" | ||
| printf '%s\n' "$releases" | ||
| echo "EOF" | ||
| } >> "$GITHUB_OUTPUT" |
❌ No changes in
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Apply multiple dependency fixes and improvements.
Checklist
git commit -S)