565995e715
- Pin all third-party actions to SHA - Gate claude.yml triggers to internal authors with Harden-Runner egress audit - Ignore fork-PR lifecycle scripts - Narrow cross-repo dispatch payloads - Add 7d npm release-age gate - Add CODEOWNERS on .github/** and .yarnrc.yml --------- Co-authored-by: prastoin <paul@twenty.com>
57 lines
2.5 KiB
YAML
57 lines
2.5 KiB
YAML
name: Yarn Install
|
|
inputs:
|
|
node-version:
|
|
required: false
|
|
default: '24'
|
|
|
|
runs:
|
|
using: 'composite'
|
|
steps:
|
|
- name: Free disk space for install
|
|
if: runner.os == 'Linux'
|
|
shell: bash
|
|
run: |
|
|
# Default GitHub images ship large SDKs this repo does not use; removing
|
|
# them avoids ENOSPC when restoring or linking a full Yarn node_modules.
|
|
sudo rm -rf /usr/share/dotnet
|
|
sudo rm -rf /usr/local/lib/android
|
|
sudo rm -rf /opt/ghc
|
|
sudo rm -rf /opt/hostedtoolcache/CodeQL
|
|
df -h
|
|
- name: Cache primary key builder
|
|
id: globals
|
|
shell: bash
|
|
run: |
|
|
echo "ACTION_SHELL=bash" >> "${GITHUB_OUTPUT}"
|
|
echo "CACHE_KEY_PREFIX=node_modules-cache-node-${{ inputs.node-version }}-${{ hashFiles('yarn.lock') }}" >> "${GITHUB_OUTPUT}"
|
|
echo 'PATH_TO_CACHE<<EOF' >> $GITHUB_OUTPUT
|
|
echo "node_modules" >> $GITHUB_OUTPUT
|
|
echo "packages/*/node_modules" >> $GITHUB_OUTPUT
|
|
echo 'EOF' >> $GITHUB_OUTPUT
|
|
- name: Setup Node.js and get yarn cache
|
|
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
|
|
with:
|
|
node-version: ${{ inputs.node-version }}
|
|
- name: Restore node_modules
|
|
id: cache-node-modules
|
|
uses: actions/cache/restore@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 (restore)
|
|
with:
|
|
key: v4-${{ steps.globals.outputs.CACHE_KEY_PREFIX }}-${{github.sha}}
|
|
restore-keys: v4-${{ steps.globals.outputs.CACHE_KEY_PREFIX }}-
|
|
path: ${{ steps.globals.outputs.PATH_TO_CACHE }}
|
|
- name: Install Dependencies
|
|
if: ${{ steps.cache-node-modules.outputs.cache-hit != 'true' && steps.cache-node-modules.outputs.cache-matched-key == '' }}
|
|
shell: ${{ steps.globals.outputs.ACTION_SHELL }}
|
|
run: |
|
|
yarn config set enableHardenedMode true
|
|
yarn config set enableScripts false
|
|
yarn --immutable --check-cache
|
|
# Fork PRs on pull_request already can't write to the base repo's cache (GitHub built-in).
|
|
# The fork guard is defense-in-depth for pull_request_target, which does have write access.
|
|
- name: Save cache
|
|
if: ${{ steps.cache-node-modules.outputs.cache-hit != 'true' && steps.cache-node-modules.outputs.cache-matched-key == '' && format('{0}', github.event.pull_request.head.repo.fork) != 'true' }}
|
|
uses: actions/cache/save@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 (save)
|
|
with:
|
|
key: ${{ steps.cache-node-modules.outputs.cache-primary-key }}
|
|
path: ${{ steps.globals.outputs.PATH_TO_CACHE }}
|