Обновление пина описано, воркфлоу перестали быть «не входом»

Комментарий с версией рядом с SHA — единственное, что говорит читателю, какой
релиз держали в руках; `docs/DEVELOPMENT.md` описывает, как посмотреть, что
сейчас за тегом, и заменить обе части одним коммитом. Отдельно записано, что у
`home-assistant/actions` и `hacs/action` тегов нет вовсе — там в комментарии
стоит дата, на которую читалась голова ветки.

Запись `NOT_AN_INPUT` для `.github/workflows/*.yml` снята: воркфлоу читает
проверка пинов, то есть они теперь честный вход, а не «у каждого свой запуск».

Issue: #556
User-Visible: no
This commit is contained in:
Codex
2026-09-13 16:24:10 +00:00
committed by claude[bot]
parent b35551884f
commit 954eeff45a
2 changed files with 22 additions and 1 deletions
+22
View File
@@ -348,6 +348,28 @@ The witness is browser-independent and lives in
`demo/smoke_marker_shadow_transitions.mjs`: change the stage container width by
one pixel and assert that no `transitionrun` for `box-shadow` arrives.
## Updating a pinned Action (#556)
Every `uses:` in `.github/workflows/**` is a full commit SHA with the human
version in a trailing comment; `node scripts/action-pins.mjs` enforces it and the
Validate preflight runs it. The comment is not decoration — it is the only thing
that tells a reader which release they audited.
To move a pin: read what the tag points at today,
```bash
gh api repos/<owner>/<repo>/commits/<tag> -q .sha
```
read the delta from the currently pinned SHA, then change **both** the SHA and
the comment in one commit. `node scripts/action-pins.mjs --list` prints every
third-party action with its pin, which is the fastest way to see what is behind.
Two of these are branches upstream, not releases — `home-assistant/actions`
(`master`) and `hacs/action` (`main`) — so their comment carries the date the
branch head was read. They have no tags to follow; the only honest record is
"this commit, read on this day".
## Dependency and cache gotchas
- **polygon-clipping is a trap**: its `.d.ts` declares named exports but the ESM build has only
-1
View File
@@ -61,7 +61,6 @@ export const NOT_AN_INPUT = [
['scripts/support-relay/deploy/**', 'деплой relay на стенд'],
['scripts/wsl-setup.sh', 'установка локального Linux/WSL-контура с пинами CI (#496), ручной запуск'],
['scripts/windows-toolchain.ps1', 'изолированная установка и запуск Windows toolchain с пинами CI (#557), ручной запуск'],
['.github/workflows/*.yml', 'другие workflow: у каждого свой запуск; validate.yml — вход toolchain всех проверок, объявлен явно'],
['.github/ISSUE_TEMPLATE/**', 'шаблоны issue GitHub, не исполняются'],
['.githooks/**', 'локальные хуки'],
];