Skip to content

chore(deps): update dependency @actions/cache to v6.1.0 (#86) #330

chore(deps): update dependency @actions/cache to v6.1.0 (#86)

chore(deps): update dependency @actions/cache to v6.1.0 (#86) #330

Workflow file for this run

name: Test
on:
push:
branches: [main]
pull_request:
branches: [main]
merge_group:
workflow_dispatch:
inputs:
pr_version:
description: "pkg.pr.new PR number or commit SHA to test an unreleased Vite+ build (e.g. 1569). Leave empty to test the latest published release."
required: false
default: ""
# Push / PR / merge_group runs always test the latest published Vite+. A manual
# workflow_dispatch can set pr_version to a PR number or commit SHA; the install
# script picks it up via VP_PR_VERSION, which overrides VP_VERSION and pulls the
# matching build from pkg.pr.new — so a new Vite+ release can be verified across
# the whole matrix before it ships. The value is empty on every other event,
# which the install script treats as "unset" and falls back to the latest release.
env:
VP_PR_VERSION: ${{ github.event.inputs.pr_version }}
jobs:
test:
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
- name: Setup Vite+
uses: ./
with:
run-install: false
cache: false
- name: Verify installation
run: vp --version
test-node-version:
strategy:
fail-fast: false
matrix:
node-version: ["lts", "20", "22", "24"]
runs-on: ubuntu-latest
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
# Create the throwaway fixture under $RUNNER_TEMP, outside the repo. The
# repo commits a pnpm-workspace.yaml (for the release-age exclude), so a
# fixture inside the repo would be treated as part of this repo's
# workspace and `vp install`/`vp run` would resolve to the repo root.
# ${RUNNER_TEMP//\\//} normalizes Windows backslashes for bash.
- name: Create test project
shell: bash
run: |
DIR="${RUNNER_TEMP//\\//}/test-project"
mkdir -p "$DIR"
# Pin pnpm to v10. Vite+'s bundled pnpm 11 requires node:sqlite
# (Node >= 22.5) and crashes on Node 20; pnpm 10 still runs on Node 20.
echo '{"name":"test-project","private":true,"packageManager":"pnpm@10.34.3"}' > "$DIR/package.json"
# Runs `vp env use <version>` then `vp install` in the test project.
- name: Setup Vite+ with Node.js ${{ matrix.node-version }}
uses: ./
with:
node-version: ${{ matrix.node-version }}
run-install: |
- cwd: ${{ runner.temp }}/test-project
cache: false
- name: Verify installation
run: vp --version
- name: Verify Node.js version
shell: bash
run: |
ACTUAL=$(node --version)
echo "Node.js version: $ACTUAL"
if [ "${{ matrix.node-version }}" != "lts" ]; then
echo "$ACTUAL" | grep -q "^v${{ matrix.node-version }}\." || (echo "Expected Node.js v${{ matrix.node-version }}.x but got $ACTUAL" && exit 1)
fi
test-cache-pnpm:
runs-on: ubuntu-latest
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
- name: Create test project with pnpm-lock.yaml
run: |
mkdir -p test-project
cd test-project
echo '{"name":"test-project","private":true}' > package.json
touch pnpm-lock.yaml
- name: Setup Vite+ with pnpm cache
uses: ./
id: setup
with:
run-install: false
cache: true
cache-dependency-path: test-project/pnpm-lock.yaml
- name: Verify installation
run: |
vp --version
echo "Installed version: ${{ steps.setup.outputs.version }}"
echo "Cache hit: ${{ steps.setup.outputs.cache-hit }}"
test-cache-npm:
runs-on: ubuntu-latest
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
- name: Create test project with package-lock.json
run: |
mkdir -p test-project
cd test-project
echo '{"name":"test-project","private":true}' > package.json
echo '{"name":"test-project","lockfileVersion":3}' > package-lock.json
- name: Setup Vite+ with npm cache
uses: ./
id: setup
with:
run-install: false
cache: true
cache-dependency-path: test-project/package-lock.json
- name: Verify installation
run: |
vp --version
echo "Installed version: ${{ steps.setup.outputs.version }}"
echo "Cache hit: ${{ steps.setup.outputs.cache-hit }}"
test-cache-yarn:
runs-on: ubuntu-latest
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
- name: Create test project with yarn.lock
run: |
mkdir -p test-project
cd test-project
echo '{"name":"test-project","private":true}' > package.json
touch yarn.lock
- name: Setup Vite+ with yarn cache
uses: ./
id: setup
with:
run-install: false
cache: true
cache-dependency-path: test-project/yarn.lock
- name: Verify installation
run: |
vp --version
echo "Installed version: ${{ steps.setup.outputs.version }}"
echo "Cache hit: ${{ steps.setup.outputs.cache-hit }}"
test-cache-bun:
strategy:
fail-fast: false
matrix:
lockfile: [bun.lock, bun.lockb]
runs-on: ubuntu-latest
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
- name: Create test project with ${{ matrix.lockfile }}
run: |
mkdir -p test-project
cd test-project
echo '{"name":"test-project","private":true}' > package.json
touch ${{ matrix.lockfile }}
- name: Setup Vite+ with bun cache (${{ matrix.lockfile }})
uses: ./
id: setup
with:
run-install: false
cache: true
cache-dependency-path: test-project/${{ matrix.lockfile }}
- name: Verify installation
run: |
vp --version
echo "Installed version: ${{ steps.setup.outputs.version }}"
echo "Cache hit: ${{ steps.setup.outputs.cache-hit }}"
test-vp-exec:
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
- name: Setup Vite+
uses: ./
with:
run-install: false
cache: false
- name: Verify vp exec works
run: vp exec node -e "console.log('vp exec works')"
test-vp-install-and-exec:
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
# Fixture lives under $RUNNER_TEMP (outside the repo) so the committed
# pnpm-workspace.yaml doesn't make vp resolve it to the repo root.
- name: Create test project
shell: bash
run: |
DIR="${RUNNER_TEMP//\\//}/test-project"
mkdir -p "$DIR"
echo '{"name":"test-project","private":true,"scripts":{"hello":"node -e \"console.log(1+1)\""}}' > "$DIR/package.json"
- name: Setup Vite+ with install
uses: ./
with:
run-install: |
- cwd: ${{ runner.temp }}/test-project
cache: false
- name: Verify vp exec in project
working-directory: ${{ runner.temp }}/test-project
run: vp exec node -e "console.log('vp exec in project works')"
- name: Verify vp run in project
working-directory: ${{ runner.temp }}/test-project
run: vp run hello
test-registry-url:
runs-on: ubuntu-latest
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
- name: Setup Vite+ with registry-url
uses: ./
with:
run-install: false
cache: false
registry-url: "https://npm.pkg.github.com"
scope: "@voidzero-dev"
- name: Verify .npmrc was created
run: |
echo "NPM_CONFIG_USERCONFIG=$NPM_CONFIG_USERCONFIG"
cat "$NPM_CONFIG_USERCONFIG"
grep -q "@voidzero-dev:registry=https://npm.pkg.github.com/" "$NPM_CONFIG_USERCONFIG"
grep -q "_authToken=\${NODE_AUTH_TOKEN}" "$NPM_CONFIG_USERCONFIG"
- name: Verify NODE_AUTH_TOKEN is exported
run: |
echo "NODE_AUTH_TOKEN is set: ${NODE_AUTH_TOKEN:+yes}"
test-alpine-container:
runs-on: ubuntu-latest
container:
image: alpine:3.24
steps:
- name: Install Alpine dependencies
run: apk add --no-cache bash curl gcompat libstdc++
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
- name: Setup Vite+
uses: ./
with:
run-install: false
cache: false
- name: Verify installation
run: vp --version
- name: Verify vp exec works
run: vp exec node -e "console.log('vp exec works in Alpine')"
test-sfw:
# sfw wraps vp install end-to-end on all OSes (macOS / Windows supported
# since vite-plus v0.1.23). On Linux we verify across every package
# manager vp auto-detects via lockfile (pnpm/npm/yarn/bun); macOS / Windows
# run pnpm only because the PM choice doesn't change the sfw wrap path —
# those cells exist to prove the cross-platform sfw download + wrap works.
# vp version follows the workflow default (`latest`, or the pr_version
# pkg.pr.new build on manual dispatch via VP_PR_VERSION) — sfw is decoupled
# from vp's release channel, so it just rides whatever vp the rest of the
# matrix is testing.
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
package-manager: [pnpm, npm, yarn, bun]
exclude:
# Non-Linux runs pnpm only — PM diversity adds no sfw-wrap coverage.
- { os: macos-latest, package-manager: npm }
- { os: macos-latest, package-manager: yarn }
- { os: macos-latest, package-manager: bun }
- { os: windows-latest, package-manager: npm }
- { os: windows-latest, package-manager: yarn }
- { os: windows-latest, package-manager: bun }
runs-on: ${{ matrix.os }}
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
# Fixture lives under $RUNNER_TEMP (outside the repo) so the committed
# pnpm-workspace.yaml doesn't make vp resolve it to the repo root.
- name: Create test project for ${{ matrix.package-manager }}
shell: bash
run: |
case "${{ matrix.package-manager }}" in
pnpm) LOCKFILE=pnpm-lock.yaml; CONTENTS='' ;;
npm) LOCKFILE=package-lock.json; CONTENTS='{"name":"test-project","lockfileVersion":3}' ;;
yarn) LOCKFILE=yarn.lock; CONTENTS='' ;;
bun) LOCKFILE=bun.lock; CONTENTS='' ;;
*) echo "Unsupported package-manager: ${{ matrix.package-manager }}" >&2; exit 1 ;;
esac
DIR="${RUNNER_TEMP//\\//}/test-project"
mkdir -p "$DIR"
echo '{"name":"test-project","private":true,"dependencies":{"is-odd":"^3.0.1"}}' > "$DIR/package.json"
printf '%s' "$CONTENTS" > "$DIR/$LOCKFILE"
- name: Configure Yarn .yarnrc.yml (Linux + yarn only)
if: matrix.package-manager == 'yarn' && runner.os == 'Linux'
# nodeLinker=node-modules: Yarn Berry defaults to Plug'n'Play, which
# makes plain `require()` from a non-yarn-wrapped node process fail.
# enableImmutableInstalls=false: Yarn Berry auto-enables immutable
# installs under CI, which makes the bootstrap from an empty
# yarn.lock fail with YN0028. Setting it here (instead of via the
# YARN_ENABLE_IMMUTABLE_INSTALLS env var) survives any future
# env-sanitization vp might apply to spawned subprocesses.
shell: bash
run: |
{
echo "nodeLinker: node-modules"
echo "enableImmutableInstalls: false"
} > "${RUNNER_TEMP//\\//}/test-project/.yarnrc.yml"
- name: Setup Vite+ with sfw + ${{ matrix.package-manager }}
uses: ./
with:
sfw: true
run-install: |
- cwd: ${{ runner.temp }}/test-project
cache: false
- name: Verify sfw is on PATH
run: sfw --version
- name: Verify dependency installed via ${{ matrix.package-manager }}
working-directory: ${{ runner.temp }}/test-project
run: vp exec node -e "console.log(require('is-odd')(3))"
test-sfw-alpine:
# vp version follows the workflow default (`latest`, or a pr_version
# pkg.pr.new build on manual dispatch) — sfw's musl asset selection is
# decoupled from vp's release channel.
# NOTE: if this job is later re-matrixed (multiple vp builds, multiple
# alpine versions, etc.), restore `strategy: { fail-fast: false }` so a
# flake in one shard doesn't cancel the others.
runs-on: ubuntu-latest
container:
image: alpine:3.24
steps:
- name: Install Alpine dependencies
run: apk add --no-cache bash curl gcompat libstdc++
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
# Fixture lives outside the repo so the committed pnpm-workspace.yaml
# doesn't make vp resolve it to the repo root. This is a container job:
# ${{ runner.temp }} would expand to the HOST path, but the shell and the
# action both run inside the container (where RUNNER_TEMP maps to /__w/_temp),
# so a host path passed via YAML wouldn't exist in the container. Use a
# literal in-container path (/tmp, outside the /__w workspace mount) that
# needs no host<->container translation.
- name: Create test project with a real dependency
run: |
mkdir -p /tmp/test-project
echo '{"name":"test-project","private":true,"dependencies":{"is-odd":"^3.0.1"}}' > /tmp/test-project/package.json
- name: Setup Vite+ with sfw (musl)
uses: ./
with:
sfw: true
run-install: |
- cwd: /tmp/test-project
cache: false
- name: Verify sfw is on PATH (musl)
run: sfw --version
- name: Verify dependency installed under sfw (musl)
working-directory: /tmp/test-project
run: vp exec node -e "console.log(require('is-odd')(3))"
test-sfw-blocks-malicious:
# Verifies sfw actually intercepts a known-malicious package, not just
# that it wraps the install. Uses `lodahs` (lodash typosquat), the same
# canary SocketDev's own workflows use:
# https://github.com/SocketDev/bun-security-scanner/blob/main/.github/workflows/test.yml
# If this job ever stops blocking, either sfw is misconfigured or the
# canary itself has been delisted — swap it for another Socket-flagged
# package from https://socket.dev/blog/category/threat-research.
# vp version follows the workflow default (`latest`, or a pr_version
# pkg.pr.new build on manual dispatch) — sfw block behavior is decoupled
# from vp's release channel.
# Runs on all three OSes: a fail-open regression in vp/sfw's proxy or CA
# handling can be platform-specific (the #73 rustls cert-trust class of
# bug was), so each OS needs its own block assertion — benign-install
# success (the test-sfw job) is not enough proof.
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
# Fixture lives under $RUNNER_TEMP (outside the repo) so the committed
# pnpm-workspace.yaml doesn't make vp resolve it to the repo root.
- name: Create test project with a benign dependency
shell: bash
run: |
DIR="${RUNNER_TEMP//\\//}/test-project"
mkdir -p "$DIR"
echo '{"name":"test-project","private":true,"dependencies":{"is-odd":"^3.0.1"}}' > "$DIR/package.json"
- name: Setup Vite+ with sfw and install benign dep
uses: ./
with:
sfw: true
run-install: |
- cwd: ${{ runner.temp }}/test-project
cache: false
- name: Assert sfw blocks malicious package (lodahs typosquat of lodash)
shell: bash
working-directory: ${{ runner.temp }}/test-project
# Exit code alone isn't sufficient: a non-zero exit from npm 404,
# network blip, or vp crash would also produce a false positive. We
# also require the literal sfw block-line for lodahs in the combined
# output so an unrelated failure doesn't get reported as "sfw blocked
# it". The block-line format observed in CI is:
# " - blocked npm package: name: lodahs; version: ...; reason: ..."
# The banner "Protected by Socket Firewall" and the "=== Socket
# Firewall ===" header are emitted on EVERY sfw invocation, so neither
# of those is a usable marker — use the unique "blocked npm package:
# name: lodahs" line instead.
run: |
set +e
OUTPUT=$(sfw vp install lodahs 2>&1)
CODE=$?
set -e
printf '%s\n' "$OUTPUT"
if [ "$CODE" -eq 0 ]; then
echo "::error::sfw failed to block lodahs on ${{ matrix.os }} — install exited 0"
exit 1
fi
if ! printf '%s' "$OUTPUT" | grep -qF -- "blocked npm package: name: lodahs"; then
echo "::error::sfw vp install exited $CODE on ${{ matrix.os }} but the lodahs block-line was not in the output — likely failed for a non-sfw reason (canary delisted, network blip, vp crash, or sfw output format changed). Swap the canary if Socket has delisted lodahs, or update the marker grep if sfw's block-line format changed."
exit 1
fi
echo "OK: sfw blocked lodahs on ${{ matrix.os }} (exit $CODE, block-line found)"
test-sfw-with-socketdev-action:
# Exercises the composition path: install sfw via the upstream
# `socketdev/action@<sha>` step first, then call setup-vp with `sfw:
# true`. setup-vp should DETECT the pre-installed sfw on PATH (via
# findSfwOnPath()) and SKIP its bundled download. We assert that by
# checking $RUNNER_TEMP/sfw-bin/sfw[.exe] — the exact path
# installSfw() would have created — was NOT created. We also assert the
# composed sfw actually BLOCKS a malicious package (lodahs), so this path
# is proven to enforce, not just to be wired up.
# See README "Advanced: stricter supply chain via socketdev/action".
runs-on: ubuntu-latest
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
# Fixture lives under $RUNNER_TEMP (outside the repo) so the committed
# pnpm-workspace.yaml doesn't make vp resolve it to the repo root.
- name: Create test project with a real dependency
shell: bash
run: |
DIR="${RUNNER_TEMP//\\//}/test-project"
mkdir -p "$DIR"
echo '{"name":"test-project","private":true,"dependencies":{"is-odd":"^3.0.1"}}' > "$DIR/package.json"
- name: Install sfw via socketdev/action
uses: socketdev/action@ba6de6cc0565af1f42295590380973573297e31f
with:
mode: firewall-free
- name: Setup Vite+ with sfw (composition path)
uses: ./
id: setup-vp
with:
sfw: true
run-install: |
- cwd: ${{ runner.temp }}/test-project
cache: false
- name: Verify setup-vp used the composed sfw (no bundled download)
shell: bash
# Negative assertion: if setup-vp had downloaded its own sfw, it
# would land at $RUNNER_TEMP/sfw-bin/sfw[.exe] (per
# getSfwBinDir() in install-sfw.ts). On the composition path the
# PATH-detection branch should fire FIRST and skip the download
# entirely, so neither file should exist.
run: |
if [ -e "$RUNNER_TEMP/sfw-bin/sfw" ] || [ -e "$RUNNER_TEMP/sfw-bin/sfw.exe" ]; then
echo "::error::setup-vp downloaded its own sfw binary even though one was pre-installed via socketdev/action. The PATH-detection branch in setupSfw() regressed."
exit 1
fi
echo "OK: setup-vp used the pre-installed sfw (no bundled download at \$RUNNER_TEMP/sfw-bin/)"
- name: Verify dependency installed under composed sfw
working-directory: ${{ runner.temp }}/test-project
run: vp exec node -e "console.log(require('is-odd')(3))"
- name: Assert composed sfw blocks malicious package (lodahs)
shell: bash
working-directory: ${{ runner.temp }}/test-project
# Proves the composition path actually enforces, not just that sfw is
# present. socketdev/action exports SFW_JSON_REPORT_PATH into the env,
# which makes sfw write its block report to JSON instead of stdout —
# we unset it here so the block-line goes to stdout, matching the
# marker check used by test-sfw-blocks-malicious.
run: |
unset SFW_JSON_REPORT_PATH
set +e
OUTPUT=$(sfw vp install lodahs 2>&1)
CODE=$?
set -e
printf '%s\n' "$OUTPUT"
if [ "$CODE" -eq 0 ]; then
echo "::error::composed sfw failed to block lodahs — install exited 0"
exit 1
fi
if ! printf '%s' "$OUTPUT" | grep -qF -- "blocked npm package: name: lodahs"; then
echo "::error::composed sfw vp install exited $CODE but the lodahs block-line was not in the output (canary delisted, network blip, or sfw output format changed)."
exit 1
fi
echo "OK: composed sfw blocked lodahs (exit $CODE, block-line found)"
build:
runs-on: ubuntu-latest
# This job verifies the action's own artifacts (dist/ committed and up to
# date, types, unit tests). Pin it to the latest published Vite+ even on a
# pr_version dispatch: a pre-release bundler could shift dist/ output and
# fail the "dist is up to date" diff for reasons unrelated to the change.
env:
VP_PR_VERSION: ""
steps:
- uses: taiki-e/checkout-action@7d1e50e93dc4fb3bba58f85018fadf77898aee8b # v1.4.2
- name: Setup Vite+ with cache
uses: ./
id: setup
with:
cache: true
node-version-file: .node-version
- name: Type check
run: vp run typecheck
- name: Check
run: vp run check
- name: Unit tests
run: vp run test
- name: Build
run: vp run build
- name: Verify dist is up to date
run: |
git diff --exit-code dist/ || (echo "dist/ is out of date. Run 'vp run build' and commit." && exit 1)