mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 18:36:15 -08:00
Supersedes the three individual Dependabot PRs (#1249, #1245, #1247) so the pinned-SHA contract stays consistent in one commit. actions/checkout v4 -> v7, actions/upload-artifact v4 -> v7 and actions/download-artifact v4 -> v8 across every workflow. docker.yml moves from checkout v6 to v7 with the rest. publish-snap.yaml keeps full-commit pins, so the three new SHAs are updated there and in the packaging policy tests that assert them (snap-workflow-policy.test-helpers.mjs, publish-snap-workflow.test.mjs, release-snap-assets.test.mjs). Each SHA was checked against the upstream tag refs: checkout 3d3c42e5 = v7.0.1, upload-artifact 043fb46d = v7.0.1, download-artifact 3e5f45b2 = v8.0.1. BUILD_ACTION_ALLOWLIST follows the unpinned bumps in build-and-make.yaml. download-artifact v8 changes two behaviours that matter for the Snap publish path, both in our favour: an artifact digest mismatch now fails the run instead of logging a warning, and the action only unzips responses whose Content-Type says zip. The publish job downloads a normal upload-artifact artifact by name, so decompression is unchanged, and it re-verifies the receipt digest itself regardless. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
60 lines
1.2 KiB
YAML
60 lines
1.2 KiB
YAML
name: Deploy Website to GitHub Pages
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- master
|
|
paths:
|
|
- 'apps/website/**'
|
|
- '.github/workflows/deploy-website.yml'
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
pages: write
|
|
id-token: write
|
|
|
|
concurrency:
|
|
group: 'pages'
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
build:
|
|
name: Build Website
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v7
|
|
|
|
- name: Install pnpm
|
|
uses: pnpm/action-setup@v4
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
cache: 'pnpm'
|
|
|
|
- name: Install dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Build website
|
|
run: pnpm nx build website
|
|
|
|
- name: Upload Pages artifact
|
|
uses: actions/upload-pages-artifact@v5
|
|
with:
|
|
path: dist/apps/website
|
|
|
|
deploy:
|
|
name: Deploy to GitHub Pages
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
environment:
|
|
name: github-pages
|
|
url: ${{ steps.deployment.outputs.page_url }}
|
|
steps:
|
|
- name: Deploy to GitHub Pages
|
|
id: deployment
|
|
uses: actions/deploy-pages@v4
|