mirror of
https://github.com/Alfresco/alfresco-ng2-components.git
synced 2026-09-09 18:03:21 +00:00
* [AAE-46514] - using by default ignore-scripts and have a trusted list for those who are trusted * [AAE-46514] - Improved the checks to cover more cases * [AAE-46514] - Fixed copilot comments * [AAE-46514] - OTher fixes * [AAE-46514] - Fixing other improvements and comments * [AAE-46514] - npmrc should be versioned to enforce the audit * [AAE-46514] - Improved code * [AAE-46514] - Removed the check on CI as we have other tools * [AAE-46514] - Improved check, updated descriptions, skip check on CI as there is already Sonar * [AAE-46514] - Reduced functions in smaller pieces * [AAE-46514] - Migrating to Pnpm to increase safety * [ci:force] - Checking * [ci:force] - Fixed complexity of the scripts * [ci:force] - Fixed complexity of the scripts * [ci:force] - Fixed wrong typing on yml * [ci:force] - Fixed sonar comments and added correct version to sha pinned action * [ci:force] - Fixed cache hit for npmn * [ci:force] - Improved eslint plugin so it can be built with standard action * [ci:force] - Improved eslint plugin so it can be built with standard action * [ci:force] - Added minimatch * [ci:force] - Fixing issues * [ci:force] - Removed 'run' as it is not needed * [ci:force] - Using audit in place of custom scripts * [ci:force] - Fixed vulnerabilities and removed custom scripts in favor of audit --critical * [ci:force] - Added minimum time for publishing to install * [ci:force] - Address issue with too new packages * [ci:force] - Address issue with too new packages
65 lines
2.3 KiB
YAML
65 lines
2.3 KiB
YAML
name: 'Setup'
|
|
description: 'Initialize cache, env var load'
|
|
inputs:
|
|
cache-suffix:
|
|
description: 'Suffix to make Nx cache key unique per job (e.g. matrix project name)'
|
|
required: false
|
|
default: 'default'
|
|
full-setup:
|
|
description: 'Run git-latest-tag, npm-tag, and before-install (requires fetch-depth: 0). Set to false for matrix jobs that only need node/cache.'
|
|
required: false
|
|
type: boolean
|
|
default: 'true'
|
|
act:
|
|
description: 'enable act debug'
|
|
required: false
|
|
type: boolean
|
|
default: 'false'
|
|
outputs:
|
|
npm-tag:
|
|
description: 'NPM tag'
|
|
value: ${{ steps.set-npm-tag.outputs.npm-tag }}
|
|
runs:
|
|
using: "composite"
|
|
steps:
|
|
- name: Set consistent machine ID for Nx cache
|
|
shell: bash
|
|
run: echo "nx-github-actions" | sudo tee /etc/machine-id > /dev/null
|
|
- name: Setup pnpm
|
|
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4.3.0
|
|
- name: Setup Node
|
|
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
|
with:
|
|
node-version-file: '.nvmrc'
|
|
cache: 'pnpm'
|
|
- name: get latest tag sha
|
|
if: ${{ inputs.full-setup == 'true' }}
|
|
id: tag-sha
|
|
uses: Alfresco/alfresco-build-tools/.github/actions/git-latest-tag@a6a8be7429080c132815d0482a55ae4fd28f15ba # v18.7.0
|
|
- name: load "NPM TAG"
|
|
if: ${{ inputs.full-setup == 'true' }}
|
|
id: set-npm-tag
|
|
uses: ./.github/actions/set-npm-tag
|
|
- name: Install dependencies
|
|
shell: bash
|
|
run: pnpm install --frozen-lockfile
|
|
- name: Security audit
|
|
shell: bash
|
|
run: pnpm audit --audit-level=critical
|
|
- name: Restore nx cache
|
|
uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
|
|
with:
|
|
path: |
|
|
nxcache
|
|
.nx
|
|
dist
|
|
key: ${{ runner.os }}-nxcache-${{ inputs.cache-suffix }}-${{ hashFiles('nx.json') }}-${{ github.sha }}
|
|
restore-keys: |
|
|
${{ runner.os }}-nxcache-${{ inputs.cache-suffix }}-${{ hashFiles('nx.json') }}-
|
|
${{ runner.os }}-nxcache-${{ inputs.cache-suffix }}-
|
|
- name: before install script
|
|
if: ${{ inputs.full-setup == 'true' }}
|
|
uses: ./.github/actions/before-install
|
|
with:
|
|
act: ${{ inputs.act }}
|