Parcourir la source

ci: avoid dependency cache and pin actions in release workflow (#14807)

edison il y a 1 mois
Parent
commit
f677d830e6
1 fichiers modifiés avec 4 ajouts et 5 suppressions
  1. 4 5
      .github/workflows/release.yml

+ 4 - 5
.github/workflows/release.yml

@@ -21,20 +21,19 @@ jobs:
     environment: Release
     steps:
       - name: Checkout
-        uses: actions/checkout@v6
+        uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
 
       - name: Install pnpm
-        uses: pnpm/action-setup@v5
+        uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
 
       - name: Install Node.js
-        uses: actions/setup-node@v6
+        uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
         with:
           node-version-file: '.node-version'
           registry-url: 'https://registry.npmjs.org'
-          cache: 'pnpm'
 
       - name: Install deps
-        run: pnpm install
+        run: pnpm install --frozen-lockfile
 
       - name: Update npm
         run: npm i -g npm@latest