diff --git a/docs/DEVELOPMENT.md b/docs/DEVELOPMENT.md index 95584ce8..38abad39 100644 --- a/docs/DEVELOPMENT.md +++ b/docs/DEVELOPMENT.md @@ -348,6 +348,28 @@ The witness is browser-independent and lives in `demo/smoke_marker_shadow_transitions.mjs`: change the stage container width by one pixel and assert that no `transitionrun` for `box-shadow` arrives. +## Updating a pinned Action (#556) + +Every `uses:` in `.github/workflows/**` is a full commit SHA with the human +version in a trailing comment; `node scripts/action-pins.mjs` enforces it and the +Validate preflight runs it. The comment is not decoration — it is the only thing +that tells a reader which release they audited. + +To move a pin: read what the tag points at today, + +```bash +gh api repos///commits/ -q .sha +``` + +read the delta from the currently pinned SHA, then change **both** the SHA and +the comment in one commit. `node scripts/action-pins.mjs --list` prints every +third-party action with its pin, which is the fastest way to see what is behind. + +Two of these are branches upstream, not releases — `home-assistant/actions` +(`master`) and `hacs/action` (`main`) — so their comment carries the date the +branch head was read. They have no tags to follow; the only honest record is +"this commit, read on this day". + ## Dependency and cache gotchas - **polygon-clipping is a trap**: its `.d.ts` declares named exports but the ESM build has only diff --git a/scripts/check-inputs.mjs b/scripts/check-inputs.mjs index d0736a2b..3ffc5a2d 100755 --- a/scripts/check-inputs.mjs +++ b/scripts/check-inputs.mjs @@ -61,7 +61,6 @@ export const NOT_AN_INPUT = [ ['scripts/support-relay/deploy/**', 'деплой relay на стенд'], ['scripts/wsl-setup.sh', 'установка локального Linux/WSL-контура с пинами CI (#496), ручной запуск'], ['scripts/windows-toolchain.ps1', 'изолированная установка и запуск Windows toolchain с пинами CI (#557), ручной запуск'], - ['.github/workflows/*.yml', 'другие workflow: у каждого свой запуск; validate.yml — вход toolchain всех проверок, объявлен явно'], ['.github/ISSUE_TEMPLATE/**', 'шаблоны issue GitHub, не исполняются'], ['.githooks/**', 'локальные хуки'], ];