From b033a565c6707ae51759317290e8812c37e59184 Mon Sep 17 00:00:00 2001 From: Taesu Date: Mon, 31 Aug 2026 07:16:31 +0900 Subject: [PATCH 1/2] ci: adopt shared CI tooling --- .github/workflows/ci.yml | 20 ++++++--------- .github/workflows/github-actions.yml | 37 ++++++++++++++++++++++++++++ 2 files changed, 44 insertions(+), 13 deletions(-) create mode 100644 .github/workflows/github-actions.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 50dc1d2..32ac336 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,31 +7,25 @@ on: branches: [main] merge_group: {} +permissions: + contents: read + jobs: test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - - uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # v6.0.8 - - - uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0 - with: - node-version-file: '.nvmrc' - registry-url: 'https://registry.npmjs.org' - cache: pnpm - - - name: Install - run: pnpm install + - uses: better-auth/shared-workflows/.github/actions/setup-pnpm@08e5520e7a829b03bee1152913682b67d2ba44b1 - name: Build run: pnpm build - + - name: Test run: pnpm test - name: Typecheck run: pnpm typecheck - \ No newline at end of file diff --git a/.github/workflows/github-actions.yml b/.github/workflows/github-actions.yml new file mode 100644 index 0000000..b033d7a --- /dev/null +++ b/.github/workflows/github-actions.yml @@ -0,0 +1,37 @@ +name: GitHub Actions + +on: + pull_request: + paths: + - ".github/actions/**" + - ".github/workflows/**" + - ".github/zizmor.yml" + push: + branches: [main] + paths: + - ".github/actions/**" + - ".github/workflows/**" + - ".github/zizmor.yml" + +permissions: {} + +jobs: + lint: + permissions: + contents: read + uses: better-auth/shared-workflows/.github/workflows/lint-github-actions.yml@08e5520e7a829b03bee1152913682b67d2ba44b1 + + zizmor: + if: github.event_name == 'pull_request' + permissions: + actions: read + contents: read + uses: better-auth/shared-workflows/.github/workflows/zizmor.yml@08e5520e7a829b03bee1152913682b67d2ba44b1 + + zizmor-code-scanning: + if: github.event_name == 'push' + permissions: + actions: read + contents: read + security-events: write + uses: better-auth/shared-workflows/.github/workflows/zizmor-code-scanning.yml@08e5520e7a829b03bee1152913682b67d2ba44b1 From 77c7b8efa22c78bb72c50d56b3ff06e6edf15f7a Mon Sep 17 00:00:00 2001 From: Taesu Date: Mon, 31 Aug 2026 07:38:50 +0900 Subject: [PATCH 2/2] ci: clarify lint workflow naming --- .../workflows/{github-actions.yml => lint-github-actions.yml} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename .github/workflows/{github-actions.yml => lint-github-actions.yml} (97%) diff --git a/.github/workflows/github-actions.yml b/.github/workflows/lint-github-actions.yml similarity index 97% rename from .github/workflows/github-actions.yml rename to .github/workflows/lint-github-actions.yml index b033d7a..07a2f2f 100644 --- a/.github/workflows/github-actions.yml +++ b/.github/workflows/lint-github-actions.yml @@ -1,4 +1,4 @@ -name: GitHub Actions +name: Lint GitHub Actions on: pull_request: