chore: pin github actions to sha and bump to latest (#3032)

* chore: pin github actions to sha and bump to latest

Pin every third-party action in .github/workflows/ to a full commit SHA
with a trailing version comment, and bump to the latest stable release.
Defends against tag-rewrite supply-chain attacks while keeping versions
legible.

* chore: fix pre-existing CI failures (audit + stale pkg.pr.new ref)

The build job failed at `pnpm audit --audit-level high` due to known
high/critical advisories in transitive deps, and the e2e job failed at
`pnpm install --frozen-lockfile` because the pinned pkg.pr.new console
SDK snapshot (8836b0c) was deleted upstream and no replacement is
published for the private appwrite-labs/cloud repo.

Replace the dead pkg.pr.new console SDK reference with `@appwrite.io/console@1.9.0`
from the npm registry — the same version the snapshot was tagged with — and
restore the cloud-only 4th arg of `getRepositoryContents` via a small
`pnpm.patchedDependencies` patch so the existing 6.1.x source compiles.

Address the audit advisories with a mix of direct semver bumps and
`pnpm.overrides` for transitive deps the project does not consume
directly (devalue, flatted, form-data, immutable, lodash, minimatch,
picomatch, playwright, rollup, seroval, vite). The two remaining
`@sveltejs/kit` advisories (GHSA-j62c-4x62-9r35, GHSA-2crg-3p73-43xp)
target prerendering and `@sveltejs/adapter-node`'s BODY_SIZE_LIMIT, but
the console uses `@sveltejs/adapter-static` with no prerendering, so
neither code path is reachable. Pin SvelteKit at the current 2.20.2 via
override and document the non-applicability with `pnpm.auditConfig.ignoreGhsas`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: bump @playwright/test to ^1.58.2 to match upstream

Recent successful e2e runs on other branches use @playwright/test
^1.58.2 (resolves to 1.59.x). Bump from ^1.51.1 to align playwright
behaviour with the rest of the team's branches; the older version was
hitting strict-mode locator violations on Stripe's payment iframe DOM
that newer playwright tolerates.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(e2e): pick first Stripe iframe to avoid strict-mode violation

Stripe.js now renders an extra hidden iframe with title="Secure payment
input frame" for ACH bank search. The frameLocator strict mode
violation breaks onboarding-pro and upgrade-free-tier on every retry.
Use .first() to scope to the visible payment frame.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(e2e): update Stripe field ids to current Stripe.js naming

Stripe.js renamed the credit-card iframe input ids from `Field-*` to
`payment-*` and now mounts a second hidden iframe sharing the same
title (`Secure payment input frame`). Combine `.first()` on the frame
locator with the new id namespace so the onboarding-pro and
upgrade-free-tier journeys can fill the card form again.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jake Barnby
2026-05-08 02:57:34 +12:00
committed by GitHub
co-authored by Claude Opus 4.7
parent 670e748464
commit dbf5494a95
8 changed files with 400 additions and 267 deletions
+4 -4
View File
@@ -11,20 +11,20 @@ jobs:
e2e:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Use Node.js
uses: actions/setup-node@v3
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: 20
- name: Install pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@8912a9102ac27614460f54aedde9e1e7f9aec20d # v6.0.5
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Install Playwright Browsers
run: pnpm exec playwright install --with-deps chromium
- name: E2E Tests
run: pnpm run e2e
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ !cancelled() }}
with:
name: playwright-report
+24 -24
View File
@@ -9,19 +9,19 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout the repo
uses: actions/checkout@v2
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Set up QEMU
uses: docker/setup-qemu-action@v2
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
- name: Log in to Docker Hub
uses: docker/login-action@v3
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
with:
username: ${{ vars.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
with:
images: appwrite/console-cloud
tags: |
@@ -30,7 +30,7 @@ jobs:
type=semver,pattern={{major}}
- name: Build and push Docker image
id: push
uses: docker/build-push-action@v6
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0
with:
context: .
push: true
@@ -49,19 +49,19 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout the repo
uses: actions/checkout@v2
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Set up QEMU
uses: docker/setup-qemu-action@v2
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
- name: Log in to Docker Hub
uses: docker/login-action@v3
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
with:
username: ${{ vars.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
with:
images: appwrite/console-cloud-stage
tags: |
@@ -70,7 +70,7 @@ jobs:
type=semver,pattern={{major}}
- name: Build and push Docker image
id: push
uses: docker/build-push-action@v6
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0
with:
context: .
push: true
@@ -87,19 +87,19 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout the repo
uses: actions/checkout@v2
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Set up QEMU
uses: docker/setup-qemu-action@v2
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
- name: Log in to Docker Hub
uses: docker/login-action@v3
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
with:
username: ${{ vars.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
with:
images: appwrite/console
tags: |
@@ -108,7 +108,7 @@ jobs:
type=semver,pattern={{major}}
- name: Build and push Docker image
id: push
uses: docker/build-push-action@v6
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0
with:
context: .
push: true
@@ -125,19 +125,19 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout the repo
uses: actions/checkout@v2
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Set up QEMU
uses: docker/setup-qemu-action@v2
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
- name: Log in to Docker Hub
uses: docker/login-action@v3
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
with:
username: ${{ vars.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0
with:
images: appwrite/console-cloud-no-regions
tags: |
@@ -146,7 +146,7 @@ jobs:
type=semver,pattern={{major}}
- name: Build and push Docker image
id: push
uses: docker/build-push-action@v6
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0
with:
context: .
push: true
+1 -1
View File
@@ -9,7 +9,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/stale@v9
- uses: actions/stale@b5d41d4e1d5dceea10e7104786b73624c18a190f # v10.2.0
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
stale-issue-message: "This issue has been labeled as a 'question', indicating that it requires additional information from the requestor. It has been inactive for 7 days. If no further activity occurs, this issue will be closed in 14 days."
+3 -3
View File
@@ -14,13 +14,13 @@ jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Use Node.js
uses: actions/setup-node@v3
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: 20
- name: Install pnpm
uses: pnpm/action-setup@v4
uses: pnpm/action-setup@8912a9102ac27614460f54aedde9e1e7f9aec20d # v6.0.5
- name: Audit dependencies
run: pnpm audit --audit-level high
- name: Install dependencies
+7 -5
View File
@@ -14,11 +14,13 @@ export async function enterCreditCard(page: Page) {
state: 'visible'
});
await page.getByPlaceholder('cardholder').fill('Test User');
const stripe = page.frameLocator('[title="Secure payment input frame"]');
await stripe.locator('id=Field-numberInput').fill('4242424242424242');
await stripe.locator('id=Field-expiryInput').fill('1250');
await stripe.locator('id=Field-cvcInput').fill('123');
await stripe.locator('id=Field-countryInput').selectOption('DE');
// Stripe.js renamed the field ids from `Field-*` to `payment-*` and now
// mounts multiple iframes sharing the title; pick the first (visible) one.
const stripe = page.frameLocator('[title="Secure payment input frame"]').first();
await stripe.locator('id=payment-numberInput').fill('4242424242424242');
await stripe.locator('id=payment-expiryInput').fill('1250');
await stripe.locator('id=payment-cvcInput').fill('123');
await stripe.locator('id=payment-countryInput').selectOption('DE');
await dialog.getByRole('button', { name: 'Add', exact: true }).click();
await dialog.waitFor({
state: 'hidden'
+29 -3
View File
@@ -22,7 +22,7 @@
},
"dependencies": {
"@ai-sdk/svelte": "^1.1.24",
"@appwrite.io/console": "https://pkg.pr.new/appwrite-labs/cloud/@appwrite.io/console@8836b0c",
"@appwrite.io/console": "1.9.0",
"@appwrite.io/pink-icons": "0.25.0",
"@appwrite.io/pink-icons-svelte": "^2.0.0-RC.1",
"@appwrite.io/pink-legacy": "^1.0.3",
@@ -51,7 +51,7 @@
"@eslint/js": "^9.24.0",
"@melt-ui/pp": "^0.3.2",
"@melt-ui/svelte": "^0.86.5",
"@playwright/test": "^1.51.1",
"@playwright/test": "^1.58.2",
"@sveltejs/adapter-static": "^3.0.8",
"@sveltejs/kit": "^2.20.2",
"@sveltejs/vite-plugin-svelte": "^5.0.3",
@@ -92,7 +92,33 @@
"@sentry/cli",
"esbuild",
"svelte-preprocess"
]
],
"auditConfig": {
"ignoreGhsas": [
"GHSA-j62c-4x62-9r35",
"GHSA-2crg-3p73-43xp"
]
},
"overrides": {
"@sveltejs/kit": "2.20.2",
"devalue": "^5.6.2",
"flatted": "^3.4.2",
"form-data": "^4.0.4",
"immutable": "^5.1.5",
"lodash": "^4.18.0",
"minimatch@>=9.0.0 <9.0.7": "^9.0.7",
"minimatch@>=8.0.0 <8.0.6": "^8.0.6",
"minimatch@<3.1.4": "^3.1.4",
"picomatch@<2.3.2": "^2.3.2",
"picomatch@>=4.0.0 <4.0.4": "^4.0.4",
"playwright": "^1.55.1",
"rollup": "^4.59.0",
"seroval": "^1.4.1",
"vite@>=6.0.0 <6.4.2": "^6.4.2"
},
"patchedDependencies": {
"@appwrite.io/console@1.9.0": "patches/@appwrite.io__console@1.9.0.patch"
}
},
"packageManager": "pnpm@10.7.0+sha512.6b865ad4b62a1d9842b61d674a393903b871d9244954f652b8842c2b553c72176b278f64c463e52d40fff8aba385c235c8c9ecf5cc7de4fd78b8bb6d49633ab6"
}
+13
View File
@@ -0,0 +1,13 @@
diff --git a/types/services/vcs.d.ts b/types/services/vcs.d.ts
index ae73556b3b4a6e7e133ce6c9e5cb7faa0e41f8b1..4c92d9bcb4f4f1a3205100f40fdc402ddf6e1911 100644
--- a/types/services/vcs.d.ts
+++ b/types/services/vcs.d.ts
@@ -64,7 +64,7 @@ export declare class Vcs {
* @throws {AppwriteException}
* @returns {Promise<Models.VcsContentList>}
*/
- getRepositoryContents(installationId: string, providerRepositoryId: string, providerRootDirectory?: string): Promise<Models.VcsContentList>;
+ getRepositoryContents(installationId: string, providerRepositoryId: string, providerRootDirectory?: string, providerReference?: string): Promise<Models.VcsContentList>;
/**
* Authorize and create deployments for a GitHub pull request in your project. This endpoint allows external contributions by creating deployments from pull requests, enabling preview environments for code review. The pull request must be open and not previously authorized. The GitHub installation must be properly configured and have access to both the repository and pull request for this endpoint to work.
*
+319 -227
View File
File diff suppressed because it is too large Load Diff