Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 20 additions & 20 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
name: cargo-deny (license policy)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
- uses: EmbarkStudios/cargo-deny-action@v2
with:
command: check licenses
Expand Down Expand Up @@ -58,7 +58,7 @@ jobs:
REDIS_URL: redis://localhost:6379
SQLX_OFFLINE: "true"
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
- name: Install pinned toolchain (rust-toolchain.toml)
run: rustup toolchain install
- uses: Swatinem/rust-cache@v2
Expand All @@ -76,11 +76,11 @@ jobs:
runs-on: ubuntu-latest
steps:
# Full history: changeset status diffs against the base branch.
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
fetch-depth: 0
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7
with:
node-version: 24
cache: pnpm
Expand Down Expand Up @@ -110,25 +110,25 @@ jobs:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- uses: docker/setup-buildx-action@v3
- uses: actions/checkout@v7
- uses: docker/setup-buildx-action@v4
- name: Log in to GHCR
if: github.event_name != 'pull_request'
uses: docker/login-action@v3
uses: docker/login-action@v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@v6
with:
images: ghcr.io/${{ github.repository }}
tags: |
type=ref,event=branch
type=ref,event=pr
type=sha
- name: Build the image for the smoke test
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
load: true
Expand All @@ -149,7 +149,7 @@ jobs:
grep -q "DATABASE_URL is required" <<<"$out" || { echo "::error::chimely did not reach config validation"; exit 1; }
docker run --rm --network none --entrypoint /bin/sleep "$SMOKE_IMAGE" 1
test "$(docker image inspect -f '{{.Config.User}}' "$SMOKE_IMAGE")" = "65532:65532"
- uses: docker/build-push-action@v6
- uses: docker/build-push-action@v7
with:
context: .
push: ${{ github.event_name != 'pull_request' }}
Expand Down Expand Up @@ -182,16 +182,16 @@ jobs:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- uses: docker/setup-buildx-action@v3
- uses: actions/checkout@v7
- uses: docker/setup-buildx-action@v4
- name: Log in to GHCR
uses: docker/login-action@v3
uses: docker/login-action@v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: build
uses: docker/build-push-action@v6
uses: docker/build-push-action@v7
with:
context: .
platforms: ${{ matrix.platform }}
Expand All @@ -203,7 +203,7 @@ jobs:
mkdir -p "${RUNNER_TEMP}/digests"
digest='${{ steps.build.outputs.digest }}'
touch "${RUNNER_TEMP}/digests/${digest#sha256:}"
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v7
with:
name: digest-${{ matrix.arch }}
path: ${{ runner.temp }}/digests/*
Expand All @@ -219,20 +219,20 @@ jobs:
contents: read
packages: write
steps:
- uses: actions/download-artifact@v4
- uses: actions/download-artifact@v8
with:
path: ${{ runner.temp }}/digests
pattern: digest-*
merge-multiple: true
- uses: docker/setup-buildx-action@v3
- uses: docker/setup-buildx-action@v4
- name: Log in to GHCR
uses: docker/login-action@v3
uses: docker/login-action@v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@v6
with:
images: ghcr.io/${{ github.repository }}
tags: |
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ jobs:
REGION: ${{ vars.REGION }}
PRERELEASE: ${{ github.event.release.prerelease }}
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- name: Extract release tag
run: echo "RELEASE_TAG=${GITHUB_REF#refs/tags/}" >> "$GITHUB_ENV"
Expand All @@ -48,18 +48,18 @@ jobs:

# Auth precedes the build so the registry cache can be read from GAR.
- name: Google Auth
uses: google-github-actions/auth@v2
uses: google-github-actions/auth@v3
with:
workload_identity_provider: projects/1042125736866/locations/global/workloadIdentityPools/github-pool/providers/github-provider
service_account: github-actions@dodopayments.iam.gserviceaccount.com

- name: Set up Cloud SDK
uses: google-github-actions/setup-gcloud@v2
uses: google-github-actions/setup-gcloud@v3

- name: Docker auth
run: gcloud auth configure-docker "${REGION}-docker.pkg.dev"

- uses: docker/setup-buildx-action@v3
- uses: docker/setup-buildx-action@v4

# `latest` tracks the newest stable release, so a pre-release publishes its
# own tag but never moves `latest`.
Expand All @@ -71,7 +71,7 @@ jobs:
echo "tags=$TAGS" >> "$GITHUB_OUTPUT"

- name: Build the image for the smoke test
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
load: true
Expand All @@ -97,7 +97,7 @@ jobs:
# Durable registry cache in GAR. The cargo-chef dependency layer is
# compiled once and reused across releases.
- name: Build and push chimely image
uses: docker/build-push-action@v6
uses: docker/build-push-action@v7
with:
context: .
push: true
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ jobs:
env:
SQLX_OFFLINE: "true"
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
- name: Install pinned toolchain (rust-toolchain.toml)
run: rustup toolchain install
- uses: Swatinem/rust-cache@v2
Expand Down
16 changes: 8 additions & 8 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,15 +41,15 @@ jobs:
contents: write
pull-requests: write
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7
with:
node-version: 24
cache: pnpm
- run: pnpm install --frozen-lockfile
- name: Open or update the Version Packages PR
uses: changesets/action@v1
uses: changesets/action@v2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

Expand All @@ -64,9 +64,9 @@ jobs:
# OIDC token for npm provenance (NPM_CONFIG_PROVENANCE on the publish step).
id-token: write
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7
with:
node-version: 24
cache: pnpm
Expand All @@ -88,7 +88,7 @@ jobs:
*) echo "provenance=false" >> "$GITHUB_OUTPUT" ;;
esac
- name: Publish to npm
uses: changesets/action@v1
uses: changesets/action@v2
with:
publish: pnpm changeset publish
createGithubReleases: false
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/sonarqube.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ jobs:
timeout-minutes: 20
steps:
- name: Checkout repository
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# full history: SonarQube needs it for blame attribution and to
# compute the new-code period
Expand All @@ -56,7 +56,7 @@ jobs:
# Pinned to a commit SHA, not a tag: this step receives SONAR_TOKEN, so
# a retargeted or compromised release tag would hand credentials to
# replacement action code.
uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8.2.1
uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
Loading