From a5e2e26bd55482ffa4fcc9c8d02d7be64c4e70ad Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 1 Sep 2026 00:35:05 +0000 Subject: [PATCH 1/3] chore(deps): update actions/checkout action to v7 --- .github/workflows/release-please.yml | 2 +- .github/workflows/test.yml | 10 +++++----- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index fa55514..b2ea1a2 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -42,7 +42,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: ref: ${{ needs.release-please.outputs.tag_name }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 7067c19..0a7f5ff 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -23,7 +23,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 with: @@ -49,7 +49,7 @@ jobs: matrix: type-checker: [mypy, pyright] steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 with: @@ -81,7 +81,7 @@ jobs: # Test only min and max supported Python versions for efficiency python-version: ["3.10", "3.14"] steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 with: @@ -161,7 +161,7 @@ jobs: # Use middle-version Python for this test python-version: ["3.12"] steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 with: @@ -226,7 +226,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 with: From a053bc2b58141140339677630c9041750281694d Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Fri, 18 Sep 2026 11:04:24 -0700 Subject: [PATCH 2/3] fix(deps): avoid persisting checkout credentials --- .github/workflows/release-please.yml | 1 + .github/workflows/test.yml | 10 ++++++++++ 2 files changed, 11 insertions(+) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index b2ea1a2..4dc3309 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -44,6 +44,7 @@ jobs: steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: + persist-credentials: false ref: ${{ needs.release-please.outputs.tag_name }} - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 0a7f5ff..a433b85 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -24,6 +24,8 @@ jobs: timeout-minutes: 10 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 with: @@ -50,6 +52,8 @@ jobs: type-checker: [mypy, pyright] steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 with: @@ -82,6 +86,8 @@ jobs: python-version: ["3.10", "3.14"] steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 with: @@ -162,6 +168,8 @@ jobs: python-version: ["3.12"] steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 with: @@ -227,6 +235,8 @@ jobs: timeout-minutes: 10 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + persist-credentials: false - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 with: From 00eb6eb1d38cdf90ea9daabc2fdbc0457ca1dc50 Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Fri, 18 Sep 2026 10:37:57 -0700 Subject: [PATCH 3/3] ci(deps): isolate Windows npm installations --- .github/workflows/test.yml | 53 ++++---------------------------------- 1 file changed, 5 insertions(+), 48 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index a433b85..128823e 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -97,36 +97,12 @@ jobs: if: matrix.os == 'windows-latest' shell: pwsh run: | - # Configure cache location (applies immediately to this step) $cacheDir = Join-Path $env:RUNNER_TEMP "npm-cache" - New-Item -ItemType Directory -Force -Path $cacheDir | Out-Null - npm config set cache $cacheDir --location=user - - # Configure prefix location (applies immediately to this step) - $globalPrefix = npm config get prefix - if (-not $globalPrefix -or $globalPrefix -eq "undefined") { - $globalPrefix = Join-Path $env:APPDATA "npm" - } - $globalPrefix = $globalPrefix.Trim() - npm config set prefix $globalPrefix --location=user - - # NOW clean and verify cache (cleans the correctly-configured cache) - npm cache clean --force - npm cache verify - - # Export settings for future steps + $globalPrefix = Join-Path $env:RUNNER_TEMP "npm-global" + New-Item -ItemType Directory -Force -Path $cacheDir, $globalPrefix | Out-Null "NPM_CONFIG_CACHE=$cacheDir" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append "NPM_CONFIG_PREFIX=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - "npm_config_prefix=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - - # Add global bin directories to PATH - $binPaths = @($globalPrefix, (Join-Path $globalPrefix "bin")) | Where-Object { Test-Path $_ } - foreach ($binPath in $binPaths) { - $binPath | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append - } - - Write-Host "npm cache: $cacheDir" - Write-Host "npm prefix: $globalPrefix" + $globalPrefix | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append - name: Install promptfoo globally run: npm install -g promptfoo@latest @@ -179,30 +155,11 @@ jobs: if: matrix.os == 'windows-latest' shell: pwsh run: | - # Configure cache location (applies immediately to this step) $cacheDir = Join-Path $env:RUNNER_TEMP "npm-cache" - New-Item -ItemType Directory -Force -Path $cacheDir | Out-Null - npm config set cache $cacheDir --location=user - - # Configure prefix location (applies immediately to this step) - $globalPrefix = npm config get prefix - if (-not $globalPrefix -or $globalPrefix -eq "undefined") { - $globalPrefix = Join-Path $env:APPDATA "npm" - } - $globalPrefix = $globalPrefix.Trim() - npm config set prefix $globalPrefix --location=user - - # NOW clean and verify cache (cleans the correctly-configured cache) - npm cache clean --force - npm cache verify - - # Export settings for future steps + $globalPrefix = Join-Path $env:RUNNER_TEMP "npm-global" + New-Item -ItemType Directory -Force -Path $cacheDir, $globalPrefix | Out-Null "NPM_CONFIG_CACHE=$cacheDir" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append "NPM_CONFIG_PREFIX=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - "npm_config_prefix=$globalPrefix" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append - - Write-Host "npm cache: $cacheDir" - Write-Host "npm prefix: $globalPrefix" # Intentionally skip installing promptfoo globally # This tests the npx fallback path