From 9d31f80f1517d6e51fd6dde8a7d17c333886773e Mon Sep 17 00:00:00 2001 From: Trask Stalnaker Date: Sat, 6 Sep 2025 11:04:34 -0700 Subject: [PATCH] Pin npm dependency version --- .github/renovate.json5 | 10 ++++++++++ .github/workflows/assign-issue-owners.yml | 2 +- 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/.github/renovate.json5 b/.github/renovate.json5 index 5b8203753..a33bfc0ed 100644 --- a/.github/renovate.json5 +++ b/.github/renovate.json5 @@ -190,6 +190,16 @@ 'npx (?[^@]+)@(?[^\\s]+)', ], }, + { + customType: 'regex', + datasourceTemplate: 'npm', + managerFilePatterns: [ + '.github/workflows/**', + ], + matchStrings: [ + 'npm install (?[^@\\s]+)@(?[^\\s]+)', + ], + }, { customType: 'regex', datasourceTemplate: 'java-version', diff --git a/.github/workflows/assign-issue-owners.yml b/.github/workflows/assign-issue-owners.yml index 232396d9c..ce92700df 100644 --- a/.github/workflows/assign-issue-owners.yml +++ b/.github/workflows/assign-issue-owners.yml @@ -20,7 +20,7 @@ jobs: uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - name: Install js-yaml - run: npm install js-yaml + run: npm install js-yaml@4.0.0 - name: Parse component label and assign owners uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1