actions/checkout v4 -> v7, actions/setup-node v4 -> v7 and pnpm/action-setup v4 -> v6. Also bumps the two pins in .github/actions/setup-workspace, which dependabot's github-actions updater never proposed: `directory: /` scans .github/workflows only, so a composite action's own `uses:` lines are invisible to it. Left alone they would have kept the repo on setup-node v4 in every lane that goes through the composite — which is every lane except the checkout steps themselves.
25 lines
647 B
YAML
25 lines
647 B
YAML
name: Setup workspace
|
|
description: >-
|
|
Install pnpm and Node, then the workspace deps with a frozen lockfile. The
|
|
repo must already be checked out — a local action's files are not on disk
|
|
until actions/checkout has run, so callers check out first, then use this.
|
|
|
|
inputs:
|
|
node-version-file:
|
|
description: File to read the Node version from
|
|
required: false
|
|
default: .nvmrc
|
|
|
|
runs:
|
|
using: composite
|
|
steps:
|
|
- uses: pnpm/action-setup@v6
|
|
|
|
- uses: actions/setup-node@v7
|
|
with:
|
|
node-version-file: ${{ inputs.node-version-file }}
|
|
cache: pnpm
|
|
|
|
- shell: bash
|
|
run: pnpm install --frozen-lockfile
|