From 161a2d1e6d62af631c56f1ee45e5e291e4430df1 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Fri, 18 Sep 2026 18:39:50 +0000 Subject: [PATCH 1/2] chore(deps): update actions/setup-node digest to 2499707 --- .github/workflows/test.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 5ba4bf5..7c85793 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -26,7 +26,7 @@ jobs: outputs: version: ${{ steps.promptfoo.outputs.version }} steps: - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 + - uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6 with: node-version: "24" package-manager-cache: false @@ -154,7 +154,7 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 + - uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6 with: node-version: ${{ matrix.node-version }} package-manager-cache: false @@ -220,7 +220,7 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 + - uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6 with: node-version: ${{ matrix.node-version }} package-manager-cache: false From 507464ffbab21d08bd259801d99663556218ab29 Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Fri, 18 Sep 2026 12:05:54 -0700 Subject: [PATCH 2/2] test(ci): enforce the setup-node cache policy --- tests/test_workflow_security.py | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 tests/test_workflow_security.py diff --git a/tests/test_workflow_security.py b/tests/test_workflow_security.py new file mode 100644 index 0000000..59c4fc2 --- /dev/null +++ b/tests/test_workflow_security.py @@ -0,0 +1,30 @@ +from pathlib import Path + +import yaml + +WORKFLOWS_DIR = Path(__file__).resolve().parents[1] / ".github" / "workflows" + + +def test_setup_node_package_manager_cache_is_disabled() -> None: + """CI uses a published npm CLI; setup-node should never cache this Python project's packages.""" + matches = 0 + for workflow in sorted(WORKFLOWS_DIR.iterdir()): + if workflow.suffix not in {".yml", ".yaml"}: + continue + + jobs = yaml.safe_load(workflow.read_text(encoding="utf-8"))["jobs"] + for job_name, job in jobs.items(): + for step in job.get("steps", []): + if not step.get("uses", "").lower().startswith("actions/setup-node@"): + continue + + matches += 1 + inputs = step.get("with", {}) + location = f"{workflow.name}, job {job_name}" + automatic = inputs.get("package-manager-cache") + assert automatic is False or (isinstance(automatic, str) and automatic.lower() == "false"), ( + f"{location}: setup-node must explicitly disable package-manager-cache" + ) + assert inputs.get("cache") in (None, ""), f"{location}: setup-node must not set an explicit cache" + + assert matches, "No actions/setup-node steps found; check that this test still covers the workflows"