diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 516d5cf..85f6a1a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -17,17 +17,17 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Node.js - uses: actions/setup-node@v7 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 26 - name: Setup Bun - uses: oven-sh/setup-bun@v2 + uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0 with: bun-version: latest @@ -35,24 +35,24 @@ jobs: run: bun install --frozen-lockfile - name: Run prek - uses: j178/prek-action@v3.0.0 + uses: j178/prek-action@4e14d07f9231acabce116ccfca13b13dd9755ece # v3.0.0 build: name: Build runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Node.js - uses: actions/setup-node@v7 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 26 - name: Setup Bun - uses: oven-sh/setup-bun@v2 + uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0 with: bun-version: latest diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index ad3cb4b..31d6c3e 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -22,22 +22,22 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Node.js - uses: actions/setup-node@v7 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: 26 - name: Setup Bun - uses: oven-sh/setup-bun@v2 + uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0 with: bun-version: latest - name: Setup Pages - uses: actions/configure-pages@v6 + uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 - name: Install dependencies run: bun install --frozen-lockfile @@ -49,13 +49,13 @@ jobs: run: bunx astro check - name: Spell check - uses: crate-ci/typos@v1.49.0 + uses: crate-ci/typos@00f422f3b19c57bc6338715ebfe3316d38768461 # v1.50.3 - name: Build run: bun run build - name: Upload artifact - uses: actions/upload-pages-artifact@v5 + uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 with: path: ./dist @@ -72,4 +72,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@v5 + uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 diff --git a/.github/zizmor.yml b/.github/zizmor.yml deleted file mode 100644 index 1209dfd..0000000 --- a/.github/zizmor.yml +++ /dev/null @@ -1,7 +0,0 @@ -# Configuration for the zizmor static analysis tool, run via prek in CI -# https://docs.zizmor.sh/configuration/ -rules: - unpinned-uses: - config: - policies: - "*": ref-pin diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 59db855..59998fd 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -1,42 +1,61 @@ +priorities: + fix: 0 + fix-eol: 20 + fix-whitespace: 30 + check: 40 + repos: - repo: https://github.com/pre-commit/pre-commit-hooks - rev: v6.0.0 + rev: 3e8a8703264a2f4a69428a0aa4dcb512790b2c8c # frozen: v6.0.0 hooks: - id: check-added-large-files args: [--maxkb=500] + priority: check - id: check-case-conflict + priority: check - id: check-merge-conflict + priority: check - id: check-json + priority: check - id: check-yaml + priority: check - id: end-of-file-fixer + priority: fix-eol - id: trailing-whitespace args: [--markdown-linebreak-ext=md] + priority: fix-whitespace - repo: https://github.com/python-jsonschema/check-jsonschema - rev: 0.37.0 + rev: 0494aa7fa1314e98913a41227d8f0a515b2c1049 # frozen: 0.38.2 hooks: - id: check-dependabot + priority: check - id: check-github-workflows + priority: check - repo: https://github.com/rhysd/actionlint - rev: v1.7.11 + rev: 914e7df21a07ef503a81201c76d2b11c789d3fca # frozen: v1.7.12 hooks: - id: actionlint + priority: check - repo: https://github.com/zizmorcore/zizmor-pre-commit - rev: v1.23.1 + rev: fa412071e4f5d44d44f9e365f4676f9df92456a2 # frozen: v1.30.1 hooks: - id: zizmor + priority: check - repo: https://github.com/crate-ci/typos - rev: v1.44.0 + rev: 00f422f3b19c57bc6338715ebfe3316d38768461 # frozen: v1.50.3 hooks: - id: typos + priority: check - repo: https://github.com/oxc-project/mirrors-oxlint - rev: v1.55.0 + rev: 7ab19fc41bc7c63cb01d4322509971371c285e16 # frozen: v1.85.0 hooks: - id: oxlint + priority: check - repo: local hooks: @@ -46,8 +65,11 @@ repos: language: system pass_filenames: false files: ^src/.*\.(ts|tsx|astro)$ + priority: check - repo: meta hooks: - id: check-hooks-apply + priority: check - id: check-useless-excludes + priority: check