From 63e06d110c39b541966f21eb04bbc317c1a3c401 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Mon, 29 Sep 2025 02:41:44 +0000 Subject: [PATCH 1/2] chore(deps): update actions/setup-node action to v5 --- .github/workflows/ci.yml | 4 ++-- .github/workflows/publish.yml | 2 +- .github/workflows/release-continuous.yml | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8e7e7a7d..988e3a41 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -55,7 +55,7 @@ jobs: uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0 - name: Set node version to ${{ matrix.node_version }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v5 with: node-version: ${{ matrix.node_version }} cache: "pnpm" @@ -106,7 +106,7 @@ jobs: uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0 - name: Set node version to LTS - uses: actions/setup-node@v4 + uses: actions/setup-node@v5 with: node-version: lts/* cache: "pnpm" diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 0ff597e6..576b2ab5 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -24,7 +24,7 @@ jobs: uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0 - name: Set node version to LTS - uses: actions/setup-node@v4 + uses: actions/setup-node@v5 with: node-version: lts/* registry-url: https://registry.npmjs.org/ diff --git a/.github/workflows/release-continuous.yml b/.github/workflows/release-continuous.yml index 645f3ddc..0bbd1221 100644 --- a/.github/workflows/release-continuous.yml +++ b/.github/workflows/release-continuous.yml @@ -14,7 +14,7 @@ jobs: - name: Install pnpm uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v5 with: node-version: lts/* # disable cache, to avoid cache poisoning (https://docs.zizmor.sh/audits/#cache-poisoning) From 7f700c37e07e240901428d8552c2e8149db1ac72 Mon Sep 17 00:00:00 2001 From: sapphi-red <49056869+sapphi-red@users.noreply.github.com> Date: Thu, 2 Oct 2025 11:41:04 +0900 Subject: [PATCH 2/2] chore: disable cache --- .github/workflows/publish.yml | 1 + .github/workflows/release-continuous.yml | 1 + 2 files changed, 2 insertions(+) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 576b2ab5..e4bd435c 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -29,6 +29,7 @@ jobs: node-version: lts/* registry-url: https://registry.npmjs.org/ # disable cache, to avoid cache poisoning (https://docs.zizmor.sh/audits/#cache-poisoning) + package-manager-cache: false - name: Disallow installation scripts run: yq '.onlyBuiltDependencies = []' -i pnpm-workspace.yaml diff --git a/.github/workflows/release-continuous.yml b/.github/workflows/release-continuous.yml index 0bbd1221..41a362fd 100644 --- a/.github/workflows/release-continuous.yml +++ b/.github/workflows/release-continuous.yml @@ -18,6 +18,7 @@ jobs: with: node-version: lts/* # disable cache, to avoid cache poisoning (https://docs.zizmor.sh/audits/#cache-poisoning) + package-manager-cache: false - name: Disallow installation scripts run: yq '.onlyBuiltDependencies = []' -i pnpm-workspace.yaml