You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Assert tool versions in CI and document unsupported platforms
Addresses code review on #1775.
The `node --version` step added with the pnpm conversion only printed the
version, so a mise-shadowed Node would have gone undetected unless a human
read the log. test.yml now compares the running major against the matrix
value and fails on mismatch. The matrix value is passed through env rather
than interpolated into the run block, which is the form zizmor's
template-injection audit flags. lint.yml has no matrix, so its step is
relabelled as the smoke check it actually is.
Shadowing is also prevented outright: every mise-action step now sets
add_shims_to_path: false, so no mise shims directory reaches PATH. The
install step runs `mise install --locked` and fails if `mise which pnpm`
returns nothing, rather than appending an empty dirname -- which is `.`
-- to $GITHUB_PATH.
test.yml and lint.yml also set `cache: false` on mise-action. With
install: false, mise-action saves a cache only inside its install branch,
so nothing there ever writes one, and the restore it would otherwise
still attempt can never hit.
release.yml's publish job now asserts npm >= 11.5.1, the invariant that
lets it pin Node 24 and skip installing npm globally. A Node downgrade
would otherwise only surface during a real release. The step sits
immediately before `npm publish`, so nothing can change PATH in between.
mise.toml's lockfile_platforms comment claimed more than the setting
delivers. `mise lock` always locks the platform it runs on, even one
excluded from that list -- verified by dropping the current platform and
regenerating, which re-added it. So the list is not a hard guard, and the
comment now says so and points at the post-regeneration check.
Records that Intel macOS and Windows ARM64 are unsupported, so excluding
macos-x64 is not a loss of support. Intel macOS could not work regardless:
pnpm 11.0.5 and later ship no darwin-x64 binary, which is why mise falls
back to the release's unrelated source-maps.tgz there. README.dev.md
gains a supported platforms section.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
0 commit comments