| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
There was a problem hiding this comment.
Removes the previous dummy fallback value for NODE_AUTH_TOKEN during registry auth setup, so the action only exports NODE_AUTH_TOKEN when it is explicitly present in the environment—preventing unintended token injection that can interfere with npm OIDC publishing flows.
Changes:
Copilot reviewed 2 out of 3 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| src/authutil.ts | Gate NODE_AUTH_TOKEN export behind an explicit presence check in process.env. |
| dist/setup/index.js | Regenerated compiled output reflecting the new export behavior. |
| __tests__/authutil.test.ts | Adds coverage for “not set” and “set to empty string” NODE_AUTH_TOKEN cases. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Sorry, something went wrong.
Co-authored-by: gowridurgad <gowridurgad@gmail.com>
Co-authored-by: gowridurgad <gowridurgad@gmail.com>
#11) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6.4.0` → `v7.0.0` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0) [Compare Source](actions/setup-node@v6.5.0...v7.0.0) #### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://github.com/gowridurgad) in [#​1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://github.com/gowridurgad) in [#​1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://github.com/gowridurgad) in [#​1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://github.com/deiga) in [#​1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​1569](actions/setup-node#1569) #### New Contributors - [@​chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#​1536](actions/setup-node#1536) - [@​deiga](https://github.com/deiga) made their first contribution in [#​1548](actions/setup-node#1548) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0) [Compare Source](actions/setup-node@v6.4.0...v6.5.0) #### What's Changed - Update [@​actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​1579](actions/setup-node#1579) **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Warsaw) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI2MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=--> Reviewed-on: https://git.ajgon.casa/deedee/schemas/pulls/11
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0. Release notes *Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).* > v7.0.0 > ------ > > What's Changed > -------------- > > ### Enhancements: > > * Add cache-primary-key and cache-matched-key as outputs by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1577](https://redirect.github.com/actions/setup-node/pull/1577) > * Migrate to ESM and upgrade dependencies by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1574](https://redirect.github.com/actions/setup-node/pull/1574) > > ### Bug fixes: > > * Remove dummy NODE\_AUTH\_TOKEN export by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1558](https://redirect.github.com/actions/setup-node/pull/1558) > * Only use `mirrorToken` in `getManifest` if it's provided by [`@deiga`](https://github.com/deiga) in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548) > > ### Documentation updates: > > * Add documentation for publishing to npm with Trusted Publisher (OIDC) by [`@chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536) > * docs: Update restore-only cache documentation by [`@priya-kinthali`](https://github.com/priya-kinthali) in [actions/setup-node#1550](https://redirect.github.com/actions/setup-node/pull/1550) > * docs: Update caching recommendations to mitigate cache poisoning risks by [`@chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1567](https://redirect.github.com/actions/setup-node/pull/1567) > > ### Dependency update: > > * Upgrade `@actions/cache` to 5.1.0, log cache write denied by [`@jasongin`](https://github.com/jasongin) in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569) > > New Contributors > ---------------- > > * [`@chiranjib-swain`](https://github.com/chiranjib-swain) made their first contribution in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536) > * [`@deiga`](https://github.com/deiga) made their first contribution in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548) > * [`@jasongin`](https://github.com/jasongin) made their first contribution in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569) > > **Full Changelog**: <actions/setup-node@v6...v7.0.0> > > v6.5.0 > ------ > > What's Changed > -------------- > > * Update `@actions/cache` to 5.1.0 and add security overrides for undici and fast-xml-parser by [`@HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-node#1579](https://redirect.github.com/actions/setup-node/pull/1579) > > **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> Commits * [`8207627`](actions/setup-node@8207627) Migrate to ESM and upgrade dependencies ([#1574](https://redirect.github.com/actions/setup-node/issues/1574)) * [`04be95c`](actions/setup-node@04be95c) Add cache-primary-key and cache-matched-key as outputs ([#1577](https://redirect.github.com/actions/setup-node/issues/1577)) * [`7c2c68d`](actions/setup-node@7c2c68d) docs: Update caching recommendations to mitigate cache poisoning risks ([#1567](https://redirect.github.com/actions/setup-node/issues/1567)) * [`6a61c03`](actions/setup-node@6a61c03) Merge pull request [#1569](https://redirect.github.com/actions/setup-node/issues/1569) from jasongin/update-actions-cache-5.1.0 * [`30eb73b`](actions/setup-node@30eb73b) Resolve high-severity audit issues * [`4e1a87a`](actions/setup-node@4e1a87a) Update dist * [`360237f`](actions/setup-node@360237f) Strict equality * [`4f8aac5`](actions/setup-node@4f8aac5) Bump `@actions/cache` to 5.1.0, log cache write denied * [`f4a67bb`](actions/setup-node@f4a67bb) Only use `mirrorToken` in `getManifest` if it's provided ([#1548](https://redirect.github.com/actions/setup-node/issues/1548)) * [`0355742`](actions/setup-node@0355742) Remove dummy NODE\_AUTH\_TOKEN export ([#1558](https://redirect.github.com/actions/setup-node/issues/1558)) * Additional commits viewable in [compare view](actions/setup-node@48b55a0...8207627) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
…roup (#558) Bumps the all-actions group with 1 update: [actions/setup-node](https://github.com/actions/setup-node). Updates `actions/setup-node` from **6** to **7** ## Release notes *Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).* > ## v7.0.0 > > ## What's Changed > > ### Enhancements > - Add `cache-primary-key` and `cache-matched-key` as outputs by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1577](actions/setup-node#1577) > - Migrate to ESM and upgrade dependencies by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1574](actions/setup-node#1574) > > ### Bug fixes > - Remove dummy `NODE_AUTH_TOKEN` export by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1558](actions/setup-node#1558) > - Only use `mirrorToken` in `getManifest` if it's provided by [@deiga](https://github.com/deiga) in [actions/setup-node#1548](actions/setup-node#1548) > > ### Documentation updates > - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@chiranjib-swain](https://github.com/chiranjib-swain) in [actions/setup-node#1536](actions/setup-node#1536) > - Update restore-only cache documentation by [@priya-kinthali](https://github.com/priya-kinthali) in [actions/setup-node#1550](actions/setup-node#1550) > - Update caching recommendations to mitigate cache poisoning risks by [@chiranjib-swain](https://github.com/chiranjib-swain) in [actions/setup-node#1567](actions/setup-node#1567) > > ### Dependency update > - Upgrade `@actions/cache` to 5.1.0, log cache write denied by [@jasongin](https://github.com/jasongin) in [actions/setup-node#1569](actions/setup-node#1569) > > ### New Contributors > - @chiranjib-swain (#1536) > - @deiga (#1548) > - @jasongin (#1569) > > **Full Changelog:** actions/setup-node@v6...v7.0.0 > > ## v6.5.0 > - Update `@actions/cache` to 5.1.0 and add security overrides for `undici` and `fast-xml-parser`. > > **Full Changelog:** actions/setup-node@v6.4.0...v6.5.0 > > ## v6.4.0 > - Upgrade `@actions` dependencies. > - Update Node.js versions in `versions.yml` and bump package to v6.4.0. > > ## v6.3.0 > - Support parsing `devEngines` field. > > ... (remaining release notes truncated exactly as in the original) ## Commits - `8207627` Migrate to ESM and upgrade dependencies (#1574) - `04be95c` Add cache-primary-key and cache-matched-key as outputs (#1577) - `7c2c68d` Update caching recommendations to mitigate cache poisoning risks (#1567) - `6a61c03` Merge pull request #1569 - `30eb73b` Resolve high-severity audit issues - `4e1a87a` Update dist - `360237f` Strict equality - `4f8aac5` Bump `@actions/cache` to 5.1.0 - `f4a67bb` Only use `mirrorToken` in `getManifest` if it's provided (#1548) - `0355742` Remove dummy `NODE_AUTH_TOKEN` export (#1558) - Additional commits viewable in the compare view. --- Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. ## Dependabot commands and options - `@dependabot rebase` - `@dependabot recreate` - `@dependabot show <dependency name> ignore conditions` - `@dependabot ignore <dependency name> major version` - `@dependabot ignore <dependency name> minor version` - `@dependabot ignore <dependency name>` - `@dependabot unignore <dependency name>` - `@dependabot unignore <dependency name> <ignore condition>`
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0) [Compare Source](actions/setup-node@v7.0.0...v7.0.0) #### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://github.com/gowridurgad) in [#​1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://github.com/gowridurgad) in [#​1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://github.com/gowridurgad) in [#​1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://github.com/deiga) in [#​1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​1569](actions/setup-node#1569) #### New Contributors - [@​chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#​1536](actions/setup-node#1536) - [@​deiga](https://github.com/deiga) made their first contribution in [#​1548](actions/setup-node#1548) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ### [`v7`](actions/setup-node@v6.5.0...v7.0.0) [Compare Source](actions/setup-node@v6.5.0...v7.0.0) ### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0) [Compare Source](actions/setup-node@v6.4.0...v6.5.0) #### What's Changed - Update [@​actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​1579](actions/setup-node#1579) **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> ### [`v6.4.0`](https://github.com/actions/setup-node/releases/tag/v6.4.0) [Compare Source](actions/setup-node@v6.3.0...v6.4.0) #### What's Changed ##### Dependency updates: - Upgrade [@​actions](https://github.com/actions) dependencies by [@​Copilot](https://github.com/Copilot) in [#​1525](actions/setup-node#1525) - Update Node.js versions in versions.yml and bump package to v6.4.0 by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1533](actions/setup-node#1533) #### New Contributors - [@​Copilot](https://github.com/Copilot) made their first contribution in [#​1525](actions/setup-node#1525) **Full Changelog**: <actions/setup-node@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-node/releases/tag/v6.3.0) [Compare Source](actions/setup-node@v6.2.0...v6.3.0) #### What's Changed ##### Enhancements: - Support parsing `devEngines` field by [@​susnux](https://github.com/susnux) in [#​1283](actions/setup-node#1283) > When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node. ##### Dependency updates: - Fix npm audit issues by [@​gowridurgad](https://github.com/gowridurgad) in [#​1491](actions/setup-node#1491) - Replace uuid with crypto.randomUUID() by [@​trivikr](https://github.com/trivikr) in [#​1378](actions/setup-node#1378) - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​1498](actions/setup-node#1498) ##### Bug fixes: - Remove hardcoded bearer for mirror-url [@​marco-ippolito](https://github.com/marco-ippolito) in [#​1467](actions/setup-node#1467) - Scope test lockfiles by package manager and update cache tests by [@​gowridurgad](https://github.com/gowridurgad) in [#​1495](actions/setup-node#1495) #### New Contributors - [@​susnux](https://github.com/susnux) made their first contribution in [#​1283](actions/setup-node#1283) **Full Changelog**: <actions/setup-node@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-node/releases/tag/v6.2.0) [Compare Source](actions/setup-node@v6.1.0...v6.2.0) #### What's Changed ##### Documentation - Documentation update related to absence of Lockfile by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​1454](actions/setup-node#1454) - Correct mirror option typos by [@​MikeMcC399](https://github.com/MikeMcC399) in [#​1442](actions/setup-node#1442) - Readme update on checkout version v6 by [@​deining](https://github.com/deining) in [#​1446](actions/setup-node#1446) - Readme typo fixes [@​munyari](https://github.com/munyari) in [#​1226](actions/setup-node#1226) - Advanced document update on checkout version v6 by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1468](actions/setup-node#1468) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5.0.1 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1449](actions/setup-node#1449) #### New Contributors - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​1454](actions/setup-node#1454) - [@​MikeMcC399](https://github.com/MikeMcC399) made their first contribution in [#​1442](actions/setup-node#1442) - [@​deining](https://github.com/deining) made their first contribution in [#​1446](actions/setup-node#1446) - [@​munyari](https://github.com/munyari) made their first contribution in [#​1226](actions/setup-node#1226) **Full Changelog**: <actions/setup-node@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-node/releases/tag/v6.1.0) [Compare Source](actions/setup-node@v6...v6.1.0) #### What's Changed ##### Enhancement: - Remove always-auth configuration handling by [@​priyagupta108](https://github.com/priyagupta108) in [#​1436](actions/setup-node#1436) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) from 4.0.3 to 4.1.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1384](actions/setup-node#1384) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1439](actions/setup-node#1439) - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1435](actions/setup-node#1435) ##### Documentation update: - Add example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1419](actions/setup-node#1419) **Full Changelog**: <actions/setup-node@v6...v6.1.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->Reviewed-on: https://gitea.com/gitea/runner/pulls/1094 Reviewed-by: Lunny Xiao <xiaolunwen@gmail.com> Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0) [Compare Source](actions/setup-node@v7.0.0...v7.0.0) ##### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://github.com/gowridurgad) in [#​1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://github.com/gowridurgad) in [#​1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://github.com/gowridurgad) in [#​1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://github.com/deiga) in [#​1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​1569](actions/setup-node#1569) ##### New Contributors - [@​chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#​1536](actions/setup-node#1536) - [@​deiga](https://github.com/deiga) made their first contribution in [#​1548](actions/setup-node#1548) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ### [`v7`](actions/setup-node@v6.5.0...v7.0.0) [Compare Source](actions/setup-node@v6.5.0...v7.0.0) ### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0) [Compare Source](actions/setup-node@v6.4.0...v6.5.0) ##### What's Changed - Update [@​actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​1579](actions/setup-node#1579) **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> ### [`v6.4.0`](https://github.com/actions/setup-node/releases/tag/v6.4.0) [Compare Source](actions/setup-node@v6.3.0...v6.4.0) ##### What's Changed ##### Dependency updates: - Upgrade [@​actions](https://github.com/actions) dependencies by [@​Copilot](https://github.com/Copilot) in [#​1525](actions/setup-node#1525) - Update Node.js versions in versions.yml and bump package to v6.4.0 by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1533](actions/setup-node#1533) ##### New Contributors - [@​Copilot](https://github.com/Copilot) made their first contribution in [#​1525](actions/setup-node#1525) **Full Changelog**: <actions/setup-node@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-node/releases/tag/v6.3.0) [Compare Source](actions/setup-node@v6.2.0...v6.3.0) ##### What's Changed ##### Enhancements: - Support parsing `devEngines` field by [@​susnux](https://github.com/susnux) in [#​1283](actions/setup-node#1283) > When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node. ##### Dependency updates: - Fix npm audit issues by [@​gowridurgad](https://github.com/gowridurgad) in [#​1491](actions/setup-node#1491) - Replace uuid with crypto.randomUUID() by [@​trivikr](https://github.com/trivikr) in [#​1378](actions/setup-node#1378) - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​1498](actions/setup-node#1498) ##### Bug fixes: - Remove hardcoded bearer for mirror-url [@​marco-ippolito](https://github.com/marco-ippolito) in [#​1467](actions/setup-node#1467) - Scope test lockfiles by package manager and update cache tests by [@​gowridurgad](https://github.com/gowridurgad) in [#​1495](actions/setup-node#1495) ##### New Contributors - [@​susnux](https://github.com/susnux) made their first contribution in [#​1283](actions/setup-node#1283) **Full Changelog**: <actions/setup-node@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-node/releases/tag/v6.2.0) [Compare Source](actions/setup-node@v6.1.0...v6.2.0) ##### What's Changed ##### Documentation - Documentation update related to absence of Lockfile by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​1454](actions/setup-node#1454) - Correct mirror option typos by [@​MikeMcC399](https://github.com/MikeMcC399) in [#​1442](actions/setup-node#1442) - Readme update on checkout version v6 by [@​deining](https://github.com/deining) in [#​1446](actions/setup-node#1446) - Readme typo fixes [@​munyari](https://github.com/munyari) in [#​1226](actions/setup-node#1226) - Advanced document update on checkout version v6 by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1468](actions/setup-node#1468) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5.0.1 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1449](actions/setup-node#1449) ##### New Contributors - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​1454](actions/setup-node#1454) - [@​MikeMcC399](https://github.com/MikeMcC399) made their first contribution in [#​1442](actions/setup-node#1442) - [@​deining](https://github.com/deining) made their first contribution in [#​1446](actions/setup-node#1446) - [@​munyari](https://github.com/munyari) made their first contribution in [#​1226](actions/setup-node#1226) **Full Changelog**: <actions/setup-node@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-node/releases/tag/v6.1.0) [Compare Source](actions/setup-node@v6...v6.1.0) #### What's Changed ##### Enhancement: - Remove always-auth configuration handling by [@​priyagupta108](https://github.com/priyagupta108) in [#​1436](actions/setup-node#1436) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) from 4.0.3 to 4.1.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1384](actions/setup-node#1384) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1439](actions/setup-node#1439) - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1435](actions/setup-node#1435) ##### Documentation update: - Add example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1419](actions/setup-node#1419) **Full Changelog**: <actions/setup-node@v6...v6.1.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->Reviewed-on: https://gitea.com/gitea/docs/pulls/467 Reviewed-by: silverwind <2021+silverwind@noreply.gitea.com> Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0) [Compare Source](actions/setup-node@v7.0.0...v7.0.0) ##### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://github.com/gowridurgad) in [#​1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://github.com/gowridurgad) in [#​1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://github.com/gowridurgad) in [#​1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://github.com/deiga) in [#​1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​1569](actions/setup-node#1569) ##### New Contributors - [@​chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#​1536](actions/setup-node#1536) - [@​deiga](https://github.com/deiga) made their first contribution in [#​1548](actions/setup-node#1548) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ### [`v7`](actions/setup-node@v6.5.0...v7.0.0) [Compare Source](actions/setup-node@v6.5.0...v7.0.0) ### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0) [Compare Source](actions/setup-node@v6.4.0...v6.5.0) ##### What's Changed - Update [@​actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​1579](actions/setup-node#1579) **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> ### [`v6.4.0`](https://github.com/actions/setup-node/releases/tag/v6.4.0) [Compare Source](actions/setup-node@v6.3.0...v6.4.0) ##### What's Changed ##### Dependency updates: - Upgrade [@​actions](https://github.com/actions) dependencies by [@​Copilot](https://github.com/Copilot) in [#​1525](actions/setup-node#1525) - Update Node.js versions in versions.yml and bump package to v6.4.0 by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1533](actions/setup-node#1533) ##### New Contributors - [@​Copilot](https://github.com/Copilot) made their first contribution in [#​1525](actions/setup-node#1525) **Full Changelog**: <actions/setup-node@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-node/releases/tag/v6.3.0) [Compare Source](actions/setup-node@v6.2.0...v6.3.0) ##### What's Changed ##### Enhancements: - Support parsing `devEngines` field by [@​susnux](https://github.com/susnux) in [#​1283](actions/setup-node#1283) > When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node. ##### Dependency updates: - Fix npm audit issues by [@​gowridurgad](https://github.com/gowridurgad) in [#​1491](actions/setup-node#1491) - Replace uuid with crypto.randomUUID() by [@​trivikr](https://github.com/trivikr) in [#​1378](actions/setup-node#1378) - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​1498](actions/setup-node#1498) ##### Bug fixes: - Remove hardcoded bearer for mirror-url [@​marco-ippolito](https://github.com/marco-ippolito) in [#​1467](actions/setup-node#1467) - Scope test lockfiles by package manager and update cache tests by [@​gowridurgad](https://github.com/gowridurgad) in [#​1495](actions/setup-node#1495) ##### New Contributors - [@​susnux](https://github.com/susnux) made their first contribution in [#​1283](actions/setup-node#1283) **Full Changelog**: <actions/setup-node@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-node/releases/tag/v6.2.0) [Compare Source](actions/setup-node@v6.1.0...v6.2.0) ##### What's Changed ##### Documentation - Documentation update related to absence of Lockfile by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​1454](actions/setup-node#1454) - Correct mirror option typos by [@​MikeMcC399](https://github.com/MikeMcC399) in [#​1442](actions/setup-node#1442) - Readme update on checkout version v6 by [@​deining](https://github.com/deining) in [#​1446](actions/setup-node#1446) - Readme typo fixes [@​munyari](https://github.com/munyari) in [#​1226](actions/setup-node#1226) - Advanced document update on checkout version v6 by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1468](actions/setup-node#1468) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5.0.1 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1449](actions/setup-node#1449) ##### New Contributors - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​1454](actions/setup-node#1454) - [@​MikeMcC399](https://github.com/MikeMcC399) made their first contribution in [#​1442](actions/setup-node#1442) - [@​deining](https://github.com/deining) made their first contribution in [#​1446](actions/setup-node#1446) - [@​munyari](https://github.com/munyari) made their first contribution in [#​1226](actions/setup-node#1226) **Full Changelog**: <actions/setup-node@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-node/releases/tag/v6.1.0) [Compare Source](actions/setup-node@v6...v6.1.0) ##### What's Changed ##### Enhancement: - Remove always-auth configuration handling by [@​priyagupta108](https://github.com/priyagupta108) in [#​1436](actions/setup-node#1436) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) from 4.0.3 to 4.1.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1384](actions/setup-node#1384) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1439](actions/setup-node#1439) - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1435](actions/setup-node#1435) ##### Documentation update: - Add example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1419](actions/setup-node#1419) **Full Changelog**: <actions/setup-node@v6...v6.1.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->Reviewed-on: https://gitea.com/gitea/blog/pulls/546 Reviewed-by: silverwind <2021+silverwind@noreply.gitea.com> Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
setup-node with registry-url writes an .npmrc containing
`_authToken=${NODE_AUTH_TOKEN}` and points NPM_CONFIG_USERCONFIG at it, so
every subsequent yarn/npm call in the job reads that file.
Through v6, setup-node also exported a dummy NODE_AUTH_TOKEN when none was
set. v7 removed that (actions/setup-node#1558). Since we publish via OIDC,
nothing sets the variable, and yarn v1 hard-fails on an unresolvable ${...}
in npmrc, so `yarn build` died before doing any work.
Move the existing "Verify npm OIDC configuration" step ahead of the build.
It already deletes the _authToken key, which strips the unresolvable
reference and leaves OIDC as the only auth mechanism.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
actions/setup-node@v7 dropped its dummy NODE_AUTH_TOKEN export (actions/setup-node#1558) but still writes an .npmrc referencing ${NODE_AUTH_TOKEN}. With cache: pnpm, pnpm shells out to read that .npmrc and aborts on the unresolved env var (pnpm#10300). Setting it explicitly to an empty string restores pre-v7 behavior; OIDC trusted publishing remains the only real auth mechanism. Fixes BRU-2031. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* ci: bump GitHub Actions off Node 20 deprecation Every action pinned in ci.yml and release-please.yml targeted Node 20, which GitHub has deprecated. Bump each to the latest published major that runs on Node 24. Version strings only — no input renames, no step or job restructuring. - actions/checkout @v4 -> @v7 (ci x1, release-please x5) - actions/setup-node @v4 -> @v7 (ci x1, release-please x4) - pnpm/action-setup @v4 -> @v6 (ci x1, release-please x2) - googleapis/release-please-action @v4 -> @v5 (release-please x1) setup-node v5 added packageManager-based auto-caching and v6 limited it to npm; caching steps set `cache: pnpm` explicitly and the project is pnpm (packageManager: pnpm@10.11.0), so no npm auto-cache is triggered. checkout v7 blocks fork-PR checkout for pull_request_target/workflow_run, neither of which these workflows use. No action input inventory changed. Refs BRU-2029 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(ci): pin empty NODE_AUTH_TOKEN for npm-publish setup-node@v7 actions/setup-node@v7 dropped its dummy NODE_AUTH_TOKEN export (actions/setup-node#1558) but still writes an .npmrc referencing ${NODE_AUTH_TOKEN}. With cache: pnpm, pnpm shells out to read that .npmrc and aborts on the unresolved env var (pnpm#10300). Setting it explicitly to an empty string restores pre-v7 behavior; OIDC trusted publishing remains the only real auth mechanism. Fixes BRU-2031. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
v7 stops exporting the dummy NODE_AUTH_TOKEN, but it still writes an .npmrc
containing ${NODE_AUTH_TOKEN} whenever registry-url is set, so every later
yarn/npm call fails with "Failed to replace env in config: ${NODE_AUTH_TOKEN}".
Upstream dropped the fallback deliberately (actions/setup-node#1558) because it
could corrupt an OIDC publish, and the fix on our side would be setting
NODE_AUTH_TOKEN on every package-manager step in every workflow.
v6 already runs on Node 24, so the deprecation this sweep exists to clear is
cleared either way. v7 only added ESM plus cache-key outputs we do not use.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
| Back | FazBrowse Home | New Git URL |
Description:
The action previously exported a dummy NODE_AUTH_TOKEN value (XXXXX-XXXXX-XXXXX-XXXXX) when no token was provided. While this didn't break OIDC flows, it could corrupt the user's .npmrc by injecting a non-functional token value into the environment, potentially causing confusing behavior during OIDC publish. This PR removes the dummy fallback and only exports NODE_AUTH_TOKEN when the user has explicitly set it.
Related issue:
#1440
Check list: