Skip to content

chore: sync workflows from Nextcloud organization#155

Open
susnux wants to merge 44 commits into
mainfrom
automated/sync-workflows
Open

chore: sync workflows from Nextcloud organization#155
susnux wants to merge 44 commits into
mainfrom
automated/sync-workflows

Conversation

@susnux
Copy link
Copy Markdown
Contributor

@susnux susnux commented Apr 26, 2026

Automated changes by create-pull-request GitHub action

dependabot Bot and others added 8 commits April 20, 2026 01:04
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.4 to 5.0.5.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@6682284...27d5ce7)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 5.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
…flow-templates/actions/cache-5.0.5

build(deps): bump actions/cache from 5.0.4 to 5.0.5 in /workflow-templates
Signed-off-by: Joas Schilling <coding@schilljs.com>
…isories

fix(psalm-phpstan): Remove roave/security-advisories
Signed-off-by: Joas Schilling <coding@schilljs.com>
ci(zizmor): Remove adjusted secrets-outside-env rule
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.0.0 to 8.1.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@cec2083...0880764)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…github/workflows/astral-sh/setup-uv-8.1.0

ci(deps): bump astral-sh/setup-uv from 8.0.0 to 8.1.0 in /.github/workflows
dependabot Bot and others added 6 commits April 27, 2026 01:04
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.3.0 to 6.4.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@53b8394...48b55a0)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 6.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…flow-templates/actions/setup-node-6.4.0

build(deps): bump actions/setup-node from 6.3.0 to 6.4.0 in /workflow-templates
Bumps [webiny/action-conventional-commits](https://github.com/webiny/action-conventional-commits) from 1.3.1 to 1.4.2.
- [Release notes](https://github.com/webiny/action-conventional-commits/releases)
- [Commits](webiny/action-conventional-commits@faccb24...7f91b15)

---
updated-dependencies:
- dependency-name: webiny/action-conventional-commits
  dependency-version: 1.4.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…flow-templates/webiny/action-conventional-commits-1.4.2

build(deps): bump webiny/action-conventional-commits from 1.3.1 to 1.4.2 in /workflow-templates
Bumps [webiny/action-conventional-commits](https://github.com/webiny/action-conventional-commits) from 1.3.1 to 1.4.2.
- [Release notes](https://github.com/webiny/action-conventional-commits/releases)
- [Commits](webiny/action-conventional-commits@faccb24...7f91b15)

---
updated-dependencies:
- dependency-name: webiny/action-conventional-commits
  dependency-version: 1.4.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…github/workflows/webiny/action-conventional-commits-1.4.2

ci(deps): bump webiny/action-conventional-commits from 1.3.1 to 1.4.2 in /.github/workflows
@susnux susnux force-pushed the automated/sync-workflows branch from 2938dfb to 6108ac9 Compare May 3, 2026 18:39
dependabot Bot and others added 2 commits May 4, 2026 01:05
Bumps [cypress-io/github-action](https://github.com/cypress-io/github-action) from 7.1.9 to 7.1.10.
- [Release notes](https://github.com/cypress-io/github-action/releases)
- [Changelog](https://github.com/cypress-io/github-action/blob/master/CHANGELOG.md)
- [Commits](cypress-io/github-action@783cb3f...c495c3d)

---
updated-dependencies:
- dependency-name: cypress-io/github-action
  dependency-version: 7.1.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
…flow-templates/cypress-io/github-action-7.1.10

build(deps): bump cypress-io/github-action from 7.1.9 to 7.1.10 in /workflow-templates
@susnux susnux force-pushed the automated/sync-workflows branch from 6108ac9 to 53a2a2b Compare May 10, 2026 18:41
dependabot Bot and others added 11 commits May 11, 2026 01:05
Bumps [cypress-io/github-action](https://github.com/cypress-io/github-action) from 7.1.10 to 7.2.0.
- [Release notes](https://github.com/cypress-io/github-action/releases)
- [Changelog](https://github.com/cypress-io/github-action/blob/master/CHANGELOG.md)
- [Commits](cypress-io/github-action@c495c3d...b7a7441)

---
updated-dependencies:
- dependency-name: cypress-io/github-action
  dependency-version: 7.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…flow-templates/cypress-io/github-action-7.2.0

build(deps): bump cypress-io/github-action from 7.1.10 to 7.2.0 in /workflow-templates
Bumps [cypress-io/github-action](https://github.com/cypress-io/github-action) from 7.2.0 to 7.3.0.
- [Release notes](https://github.com/cypress-io/github-action/releases)
- [Changelog](https://github.com/cypress-io/github-action/blob/master/CHANGELOG.md)
- [Commits](cypress-io/github-action@b7a7441...dace029)

---
updated-dependencies:
- dependency-name: cypress-io/github-action
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…flow-templates/cypress-io/github-action-7.3.0

build(deps): bump cypress-io/github-action from 7.2.0 to 7.3.0 in /workflow-templates
Signed-off-by: Joas Schilling <coding@schilljs.com>
…hp-verison

fix(psalm-matrix): Fix PHP version pick up from matrix job
Signed-off-by: Joas Schilling <coding@schilljs.com>
Signed-off-by: Joas Schilling <coding@schilljs.com>
Signed-off-by: Joas Schilling <coding@schilljs.com>
Signed-off-by: Joas Schilling <coding@schilljs.com>
nickvergessen and others added 17 commits May 15, 2026 18:04
Signed-off-by: Joas Schilling <coding@schilljs.com>
Signed-off-by: Joas Schilling <coding@schilljs.com>
Signed-off-by: Joas Schilling <coding@schilljs.com>
Defense in depth and consistency alignment with command-3rdparty's implementation:

- Switch checkout to persist-credentials: false so the PAT is not
  in the credential store during npm ci / npm run build
- Add explicit git remote set-url before push steps
- Move all ${{ }} interpolations in run: blocks to env: variables

Signed-off-by: Josh <josh.t.richards@gmail.com>
Signed-off-by: Josh <josh.t.richards@gmail.com>
ci(cmd-compile): use persist-credentials: false and env indirection
The risks of breaking your app with unchecked major updates is quite
high, so we can approve but the maintainer should at least manually
merge the PR for major updates.

Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>
fix(dependabot): only auto-merge minor and patch updates
`github.event.pull_request` is the pull request object not the event
object, so `.action` always resolves to null and breaks auto-merge.

Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>
We do not have Node.JS applications but this workflow
just checks if it can build the Javascript frontend using `npm build`.
This should reduce confusion about the workflows intend.

Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>
Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>
The auto-approve action is unmaintained currently and still uses Node 20
which is deprecated by GitHub and will be removed soon.
Auto-approve can be replaced with a 1-line `gh` script.

Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>
fix: use one-line `gh` script instead of unmaintained action
fix: correctly use `github.event.action` to fetch the type of event
chore: rename `node` to `npm-build` workflow
Signed-off-by: nextcloud-command <nextcloud-command@users.noreply.github.com>
@susnux susnux force-pushed the automated/sync-workflows branch from 53a2a2b to 89473a4 Compare May 17, 2026 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants