aa06d68ca6
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
52 lines
1.6 KiB
YAML
52 lines
1.6 KiB
YAML
name: Lockfile
|
|
|
|
on:
|
|
pull_request:
|
|
concurrency:
|
|
group: "${{ github.workflow }}-${{ github.head_ref || github.ref }}"
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
verify-pnpm-lock:
|
|
name: No manual pnpm-lock.yaml edits
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: ⬇️ Check out PR HEAD
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: ⬇️ Fetch base branch
|
|
env:
|
|
BASE_REF: ${{ github.base_ref }}
|
|
run: git fetch origin $BASE_REF --depth=1
|
|
|
|
- uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6.0.9
|
|
|
|
- name: 🔧 Install node
|
|
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version-file: package.json
|
|
|
|
- name: ⏪ Reset pnpm-lock.yaml to base
|
|
env:
|
|
BASE_REF: ${{ github.base_ref }}
|
|
run: git show "origin/$BASE_REF:pnpm-lock.yaml" > pnpm-lock.yaml
|
|
|
|
- name: 📦 pnpm install
|
|
# Fine to skip scripts since we don't run any code
|
|
run: pnpm clean && pnpm install --ignore-scripts --no-frozen-lockfile
|
|
|
|
- name: 🔍 Verify pnpm-lock.yaml
|
|
run: |
|
|
git diff --quiet --exit-code || {
|
|
echo '::error::`pnpm-lock.yaml` does not match what pnpm would generate given the base `pnpm-lock.yaml` and the head `package.json`.'
|
|
echo '::error:: - If this is intentional, you can ignore this check.'
|
|
echo '::error:: - If this is unintentional, apply the following diff:'
|
|
git --no-pager diff
|
|
exit 1
|
|
}
|