Skip to content

Commit e65d556

Browse files
authored
ci: pin coverage Python/gcovr and align lockfile docs (#25704)
- Pin coverage job to Python 3.12 and gcovr==8.6 - Record package 3.4.0 in package-lock.json - Name package-lock.json instead of a missing shrinkwrap in SECURITY.md
1 parent 4f93644 commit e65d556

3 files changed

Lines changed: 5 additions & 6 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -35,10 +35,9 @@ jobs:
3535
node-version: 22
3636
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
3737
with:
38-
python-version: '3.x'
38+
python-version: '3.12'
3939
- name: Install gcovr
40-
run: |
41-
gcovr --version || pip install --upgrade gcovr
40+
run: pip install gcovr==8.6
4241
- name: Install dependencies
4342
run: npm ci
4443
# Fails the job when JS or native coverage drops below 95%.

‎SECURITY.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -76,7 +76,7 @@ that cap throws `msgpack pack limit exceeded` without walking the holes.
7676
The pins below are inventory, not a calendar SLA:
7777

7878
- msgpack-c **c-7.0.2** (`e17beb371b59459a13b48e166a11e123bda5bf93`)
79-
- NAN **2.28.0** (compile-in; exact in `package.json` / shrinkwrap)
79+
- NAN **2.28.0** (compile-in; exact in `package.json` + `package-lock.json`)
8080

8181
Risk-based window:
8282

‎package-lock.json‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)