From 0747ec94257e93a8cde0c00fa929f3d10e9b82f2 Mon Sep 17 00:00:00 2001 From: Thibaud-Vdb Date: Fri, 18 Sep 2026 17:12:13 +0200 Subject: [PATCH 1/4] Pin third-party workflow actions to commit SHAs Tags and branches can be moved to new code at any time, so a ref like coverallsapp/github-action@master or pnpm/action-setup@v6.1.0 runs whatever it points to on the day of the run. A commit SHA cannot move. Each pin is the commit the current ref resolves to today, so nothing changes in what runs. The version comment keeps them readable and lets dependabot keep bumping them as it does now. coverallsapp/github-action@master is pinned to the head of master, which has not moved since April 2023 (it is the v1 line, the maintained releases are v2). preactjs/compressed-size-action@v3 is a branch with no v3 tag, so it is pinned to that branch head. actions/* stay on their tags. --- .github/workflows/ci.yml | 10 +++++----- .github/workflows/compressed-size.yml | 4 ++-- .github/workflows/deploy-docs.yml | 2 +- .github/workflows/release-drafter.yml | 2 +- .github/workflows/release.yml | 4 ++-- 5 files changed, 11 insertions(+), 11 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 378cff866e7..c4df61df112 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -31,13 +31,13 @@ jobs: steps: - uses: actions/checkout@v7 - - uses: pnpm/action-setup@v6.1.0 + - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - name: Use Node.js uses: actions/setup-node@v7 with: node-version: 24 cache: pnpm - - uses: dorny/paths-filter@v3 + - uses: dorny/paths-filter@0e4a8c6effa4802afeda77dc8d303f8176d7dfad # v3.0.4 id: changes with: filters: | @@ -83,7 +83,7 @@ jobs: if: | steps.changes.outputs.src == 'true' && runner.os != 'Windows' - uses: coverallsapp/github-action@master + uses: coverallsapp/github-action@09b709cf6a16e30b0808ba050c7a6e8a5ef13f8d # master with: github-token: ${{ secrets.github_token }} path-to-lcov: './coverage/chrome/lcov.info' @@ -93,7 +93,7 @@ jobs: if: | steps.changes.outputs.src == 'true' && runner.os != 'Windows' - uses: coverallsapp/github-action@master + uses: coverallsapp/github-action@09b709cf6a16e30b0808ba050c7a6e8a5ef13f8d # master with: github-token: ${{ secrets.github_token }} path-to-lcov: './coverage/firefox/lcov.info' @@ -108,7 +108,7 @@ jobs: steps: - name: Coveralls Finished if: needs.build.outputs.coveralls == 'true' - uses: coverallsapp/github-action@master + uses: coverallsapp/github-action@09b709cf6a16e30b0808ba050c7a6e8a5ef13f8d # master with: github-token: ${{ secrets.github_token }} parallel-finished: true diff --git a/.github/workflows/compressed-size.yml b/.github/workflows/compressed-size.yml index db082674488..985ede10fe1 100644 --- a/.github/workflows/compressed-size.yml +++ b/.github/workflows/compressed-size.yml @@ -17,9 +17,9 @@ jobs: steps: - uses: actions/checkout@v7 - - uses: pnpm/action-setup@v6.1.0 + - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - run: pnpm install - - uses: preactjs/compressed-size-action@v3 + - uses: preactjs/compressed-size-action@261e5e2bb5332e35c78914ce69b4edcdf30da2ed # v3 with: repo-token: "${{ secrets.GITHUB_TOKEN }}" build-script: "pnpm run build" diff --git a/.github/workflows/deploy-docs.yml b/.github/workflows/deploy-docs.yml index d4d7554bbe6..c05a4d4fba1 100644 --- a/.github/workflows/deploy-docs.yml +++ b/.github/workflows/deploy-docs.yml @@ -24,7 +24,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: pnpm/action-setup@v6.1.0 + - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - name: Use Node.js uses: actions/setup-node@v7 with: diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml index 04609ba4def..9515099cc27 100644 --- a/.github/workflows/release-drafter.yml +++ b/.github/workflows/release-drafter.yml @@ -26,6 +26,6 @@ jobs: needs: correct_repository runs-on: ubuntu-latest steps: - - uses: release-drafter/release-drafter@v6 + - uses: release-drafter/release-drafter@6a93d829887aa2e0748befe2e808c66c0ec6e4c7 # v6.4.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 21e04364dc3..acf03d2cbc9 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -27,7 +27,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: pnpm/action-setup@v6.1.0 + - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - uses: actions/setup-node@v7 with: registry-url: https://registry.npmjs.org/ @@ -72,7 +72,7 @@ jobs: if: "!github.event.release.prerelease" steps: - uses: actions/checkout@v7 - - uses: pnpm/action-setup@v6.1.0 + - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - uses: actions/setup-node@v7 with: registry-url: https://registry.npmjs.org/ From 0c1648bee6da32e3114c569138070983cd4ce3f6 Mon Sep 17 00:00:00 2001 From: Thibaud-Vdb Date: Fri, 18 Sep 2026 17:12:28 +0200 Subject: [PATCH 2/4] Do not persist the checkout token in workflow jobs actions/checkout writes the job token into the git config by default so later steps can push. None of these jobs push through it: the docs deploys clone chartjs.github.io with GH_AUTH_TOKEN in the URL, and compressed-size-action only fetches the base branch of this public repo. Leaving the token on disk only makes it readable by every later step, including pnpm install and whatever dependency scripts it runs, in the release job that holds contents: write. --- .github/workflows/ci.yml | 2 ++ .github/workflows/compressed-size.yml | 2 ++ .github/workflows/deploy-docs.yml | 2 ++ .github/workflows/release.yml | 4 ++++ 4 files changed, 10 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c4df61df112..c892d38f65a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -31,6 +31,8 @@ jobs: steps: - uses: actions/checkout@v7 + with: + persist-credentials: false - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - name: Use Node.js uses: actions/setup-node@v7 diff --git a/.github/workflows/compressed-size.yml b/.github/workflows/compressed-size.yml index 985ede10fe1..096adae527d 100644 --- a/.github/workflows/compressed-size.yml +++ b/.github/workflows/compressed-size.yml @@ -17,6 +17,8 @@ jobs: steps: - uses: actions/checkout@v7 + with: + persist-credentials: false - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - run: pnpm install - uses: preactjs/compressed-size-action@261e5e2bb5332e35c78914ce69b4edcdf30da2ed # v3 diff --git a/.github/workflows/deploy-docs.yml b/.github/workflows/deploy-docs.yml index c05a4d4fba1..48b964d10f7 100644 --- a/.github/workflows/deploy-docs.yml +++ b/.github/workflows/deploy-docs.yml @@ -24,6 +24,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 + with: + persist-credentials: false - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - name: Use Node.js uses: actions/setup-node@v7 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index acf03d2cbc9..124b2aa4f8a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -27,6 +27,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 + with: + persist-credentials: false - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - uses: actions/setup-node@v7 with: @@ -72,6 +74,8 @@ jobs: if: "!github.event.release.prerelease" steps: - uses: actions/checkout@v7 + with: + persist-credentials: false - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - uses: actions/setup-node@v7 with: From 1d8c15ab01e86a5c70879ba9bd6533b0b86b6369 Mon Sep 17 00:00:00 2001 From: Thibaud-Vdb Date: Fri, 18 Sep 2026 17:12:46 +0200 Subject: [PATCH 3/4] Build releases without restoring the pnpm cache The release jobs restored the pnpm store through setup-node's cache, which the CI and docs runs on master also save to, and a release run on a tag can read master's caches. Whatever lands in that cache is then installed by the job that publishes chart.js to npm and uploads the release tarball. Installing from the registry on release costs a minute and keeps the published build independent of anything an earlier run left behind. CI and the docs deploy keep their cache. --- .github/workflows/release.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 124b2aa4f8a..a44738c1b8d 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -34,7 +34,6 @@ jobs: with: registry-url: https://registry.npmjs.org/ node-version: 24 - cache: pnpm - name: Setup and build run: | pnpm install @@ -81,7 +80,6 @@ jobs: with: registry-url: https://registry.npmjs.org/ node-version: 24 - cache: pnpm - name: Setup and build run: | pnpm install From 9863920edd7d1555a378f1d7e6682f158c5b0ba9 Mon Sep 17 00:00:00 2001 From: Thibaud-Vdb Date: Fri, 18 Sep 2026 17:13:11 +0200 Subject: [PATCH 4/4] Replace the archived upload-release-asset action actions/upload-release-asset is archived and no longer maintained, and it still runs in the release job that holds contents: write. Its README points to softprops/action-gh-release as the maintained replacement. On a published release it finds the release from the tag being built and uploads chart.js-.tgz to it, the same asset as before. The release name, notes and prerelease flag are kept as they are. fail_on_unmatched_files keeps the step failing if the tarball is missing, as the old action did. It is pinned to the v3.0.3 commit. --- .github/workflows/release.yml | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index a44738c1b8d..cbd77b395bd 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -22,7 +22,7 @@ jobs: release: permissions: - contents: write # for actions/upload-release-asset to upload release asset + contents: write # for softprops/action-gh-release to upload release asset needs: setup runs-on: ubuntu-latest steps: @@ -58,15 +58,10 @@ jobs: VERSION: ${{ needs.setup.outputs.version }} - name: Upload NPM package file id: upload-npm-package-file - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - VERSION: ${{ needs.setup.outputs.version }} + uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3 with: - upload_url: ${{ github.event.release.upload_url }} - asset_path: ${{ format('chart.js-{0}.tgz', needs.setup.outputs.version) }} - asset_name: ${{ format('chart.js-{0}.tgz', needs.setup.outputs.version) }} - asset_content_type: application/gzip + files: ${{ format('chart.js-{0}.tgz', needs.setup.outputs.version) }} + fail_on_unmatched_files: true release-tag: needs: [setup, release] runs-on: ubuntu-latest