Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .changeset/dependency-updates-2026-09.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
---
---
2 changes: 1 addition & 1 deletion .github/workflows/autofix.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,4 +15,4 @@ permissions:

jobs:
dependabot-bun-dedupe:
uses: stella/.github/.github/workflows/dependabot-bun-dedupe.yml@dd6e8fa51339814159486cd92b5ae3a051eb15d2
uses: stella/.github/.github/workflows/dependabot-bun-dedupe.yml@636b7841096c8f0cc5a1572077b78768ef8fea42
12 changes: 6 additions & 6 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@ jobs:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v6
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.21.1"
- run: node scripts/version-sync.mjs check
Expand Down Expand Up @@ -143,7 +143,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
- run: bun install --frozen-lockfile
- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
- name: Install pinned cross-language oracle packages
run: |
uv venv .venv --python python3
Expand Down Expand Up @@ -217,7 +217,7 @@ jobs:
# snapshot-hygiene gate, `cargo ci-snapshot`); avoids a from-source
# compile on every CI run. taiki-e/install-action verifies release
# checksums, unlike a raw `curl | tar`.
uses: taiki-e/install-action@3f74d7c16a4242f1c95561e98edc25d36adb4375 # v2.87.12
uses: taiki-e/install-action@94c31af3204a9f15ab40b35ad084410b905bbc73 # v2.87.17
with:
tool: nextest@0.9.140,cargo-deny@0.20.2,cargo-insta@1.48.0

Expand Down Expand Up @@ -274,7 +274,7 @@ jobs:
- name: Install the WebAssembly build toolchain
run: |
rustup target add wasm32-unknown-unknown --toolchain 1.96.0
cargo install wasm-bindgen-cli --version 0.2.126 --locked
cargo install wasm-bindgen-cli --version 0.2.128 --locked
- run: bun run typecheck
- run: bun run build
- run: bun run performance
Expand All @@ -284,7 +284,7 @@ jobs:
- run: bun run smoke:wasm
- run: bun run smoke:browser
- run: bun run readme:check
- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
- name: Build the Python abi3 wheel
uses: PyO3/maturin-action@e83996d129638aa358a18fbd1dfb82f0b0fb5d3b # v1.51.0
with:
Expand Down Expand Up @@ -317,7 +317,7 @@ jobs:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v6
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.21.1"
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/cla.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
|| github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA'
)
)
uses: stella/.github/.github/workflows/cla.yml@48aacae31829ce15216a6b766b03a92fd2e84da3
uses: stella/.github/.github/workflows/cla.yml@636b7841096c8f0cc5a1572077b78768ef8fea42
with:
allowlist: dependabot[bot],renovate[bot],github-actions[bot],google-labs-jules[bot],cursoragent,stella-provenance-updater[bot],autofix-ci[bot]
secrets:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/mutants.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ jobs:
- name: Install pinned Rust tools (checksum-verified)
# nextest is the test runner used by cargo-mutants. taiki-e/install-action
# verifies release checksums, unlike a raw `curl | tar`.
uses: taiki-e/install-action@3f74d7c16a4242f1c95561e98edc25d36adb4375 # v2.87.12
uses: taiki-e/install-action@94c31af3204a9f15ab40b35ad084410b905bbc73 # v2.87.17
with:
tool: nextest@0.9.140,cargo-mutants@27.1.0

Expand Down Expand Up @@ -68,7 +68,7 @@ jobs:

- name: Upload mutants report
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v5
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: mutants-report
path: mutants-out/
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/quarantine-policy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,4 @@ jobs:
if: github.repository == 'stella/stdnum'
permissions:
contents: read
uses: stella/.github/.github/workflows/quarantine-policy.yml@9e1915536efc226c5ec9d3ca0f2192be5aa6ec7e
uses: stella/.github/.github/workflows/quarantine-policy.yml@636b7841096c8f0cc5a1572077b78768ef8fea42
2 changes: 1 addition & 1 deletion .github/workflows/quarantine-prune.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ jobs:
if: github.repository == 'stella/stdnum'
permissions:
contents: read
uses: stella/.github/.github/workflows/quarantine-prune.yml@9e1915536efc226c5ec9d3ca0f2192be5aa6ec7e
uses: stella/.github/.github/workflows/quarantine-prune.yml@636b7841096c8f0cc5a1572077b78768ef8fea42
secrets:
CHANGELOG_APP_ID: ${{ secrets.CHANGELOG_APP_ID }}
CHANGELOG_APP_PRIVATE_KEY: ${{ secrets.CHANGELOG_APP_PRIVATE_KEY }}
2 changes: 1 addition & 1 deletion .github/workflows/release-policy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,6 @@ permissions:
jobs:
enforce:
name: Enforce release boundaries
uses: stella/.github/.github/workflows/release-policy.yml@0f814e1a0c6c7401778e661209553b6e15f8d92a
uses: stella/.github/.github/workflows/release-policy.yml@636b7841096c8f0cc5a1572077b78768ef8fea42
permissions:
contents: read
6 changes: 4 additions & 2 deletions .github/workflows/release-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ on:

concurrency:
group: release-pr-${{ github.ref }}
cancel-in-progress: true
cancel-in-progress: false

permissions: {}

Expand All @@ -15,7 +15,9 @@ jobs:
name: Maintain version packages PR
permissions:
contents: read
uses: stella/.github/.github/workflows/changeset-release-pr.yml@c56b0c1d1e82f5e3fffa733a32b9a503a172ee35
pull-requests: read
checks: read
uses: stella/.github/.github/workflows/changeset-release-pr.yml@636b7841096c8f0cc5a1572077b78768ef8fea42
with:
bun-version-file: package.json
sync-cargo-inherited-lock: true
Expand Down
14 changes: 7 additions & 7 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ jobs:
with:
bun-version-file: package.json

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v6
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.21.1"

Expand Down Expand Up @@ -137,7 +137,7 @@ jobs:
with:
bun-version-file: package.json

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v6
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.21.1"

Expand Down Expand Up @@ -191,7 +191,7 @@ jobs:
with:
bun-version-file: package.json

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v6
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.21.1"

Expand All @@ -203,7 +203,7 @@ jobs:
rustup toolchain install 1.96.0 --profile minimal
rustup target add wasm32-unknown-unknown --toolchain 1.96.0
rustup default 1.96.0
cargo install wasm-bindgen-cli --version 0.2.126 --locked
cargo install wasm-bindgen-cli --version 0.2.128 --locked

- name: Build portable packages
run: |
Expand Down Expand Up @@ -331,7 +331,7 @@ jobs:
id-token: write # Required only for PyPI trusted publishing.
steps:
- name: Prepare exact Python wheel set
uses: stella/.github/.github/actions/pypi-publish-hardened@0f814e1a0c6c7401778e661209553b6e15f8d92a
uses: stella/.github/.github/actions/pypi-publish-hardened@636b7841096c8f0cc5a1572077b78768ef8fea42
with:
expected-version: ${{ needs.verify.outputs.version }}
project-name: stella-stdnum
Expand All @@ -344,7 +344,7 @@ jobs:
packages-dir: dist
skip-existing: true
- name: Verify published PyPI files
uses: stella/.github/.github/actions/pypi-publish-hardened/verify@0f814e1a0c6c7401778e661209553b6e15f8d92a
uses: stella/.github/.github/actions/pypi-publish-hardened/verify@636b7841096c8f0cc5a1572077b78768ef8fea42
with:
expected-version: ${{ needs.verify.outputs.version }}
project-name: stella-stdnum
Expand All @@ -354,7 +354,7 @@ jobs:
needs:
[verify, pack-native, pack-portable, publish-pypi]
if: github.ref == 'refs/heads/main' && (needs.verify.outputs.publish == 'true')
uses: stella/.github/.github/workflows/npm-version-finalize.yml@0f814e1a0c6c7401778e661209553b6e15f8d92a
uses: stella/.github/.github/workflows/npm-version-finalize.yml@636b7841096c8f0cc5a1572077b78768ef8fea42
with:
package-files: |
packages/stdnum/package.json
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,6 @@ jobs:
publish_results: true

- name: Upload SARIF to GitHub Security tab
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
sarif_file: results.sarif
Loading
Loading