Bump eslint from 10.5.0 to 10.11.0 and package.json from 7.0.0 to 7.1.0 (#1635)
- Bump eslint from 10.5.0 to 10.11.0
Bumps eslint from 10.5.0 to 10.11.0.
updated-dependencies:
- dependency-name: eslint dependency-version: 10.11.0 dependency-type: direct:development update-type: version-update:semver-minor …
Signed-off-by: dependabot[bot] support@github.com
- Bump version from 7.0.0 to 7.1.0 in package.json and package-lock.json
Signed-off-by: dependabot[bot] support@github.com Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: mahabaleshwars 147705296+mahabaleshwars@users.noreply.github.com
版权所有:中国计算机学会技术支持:开源发展技术委员会
京ICP备13000930号-9
京公网安备 11010802047560号
setup-node
This action provides the following functionality for GitHub Actions users:
What’s new in V7
@actions/*packages. No changes to action inputs, outputs, or behavior.Breaking change
NODE_AUTH_TOKENfallback has been removed, as it could unintentionally affect the generated.npmrcwith a non-functional token. With this change, ifregistry-urlis set withoutNODE_AUTH_TOKEN, legacy Yarn Classic (1.x) and older Node/npm versions may fail, and pnpm may warn. npm Trusted Publishing (OIDC) is not affected, since it does not useNODE_AUTH_TOKEN.Breaking changes in V6
Caching is now automatically enabled for npm projects when either the
devEngines.packageManagerfield or the top-levelpackageManagerfield inpackage.jsonis set tonpm. For other package managers, such as Yarn and pnpm, caching is disabled by default and must be configured manually using thecacheinput.The
always-authinput has been removed, as it is deprecated and will no longer be supported in future npm releases. To ensure your workflows continue to run without warnings or errors, please remove any references toalways-authfrom your configuration.Breaking changes in V5
Enabled caching by default with package manager detection if no cache input is provided.
Upgraded action from node20 to node24.
For more details, see the full release notes on the releases page
Usage
See action.yml
Basic:
The
node-versioninput is optional. If not supplied, the node version from PATH will be used. However, it is recommended to always specify Node.js version and not rely on the system one.The action will first check the local cache for a semver match. If unable to find a specific version in the cache, the action will attempt to download a version of Node.js. It will pull LTS versions from node-versions releases and on miss or failure will fall back to the previous behavior of downloading directly from node dist.
For information regarding locally cached versions of Node.js on GitHub hosted runners, check out GitHub Actions Runner Images.
Supported version syntax
The
node-versioninput supports the Semantic Versioning Specification, for more detailed examples please refer to the semver package documentation.Examples:
22,2420.19,22.17.1,24.8.0lts/iron,lts/jod,lts/*,lts/-n*orlatest/current/nodeNote: Like the other values,
*will get the latest locally-cached Node.js version, or the latest version from actions/node-versions, depending on thecheck-latestinput.current/latest/nodealways resolve to the latest dist version. That version is then downloaded from actions/node-versions if possible, or directly from Node.js if not. Since it will not be cached always, there is possibility of hitting rate limit when downloading from distChecking in lockfiles
It’s strongly recommended to commit the lockfile of your package manager for security and performance reasons. For more information consult the “Working with lockfiles” section of the Advanced usage guide.
Caching global packages data
The action has a built-in functionality for caching and restoring dependencies. It uses actions/cache under the hood for caching global packages data but requires less configuration settings. Supported package managers are
npm,yarn,pnpm(v6.10+). Thecacheinput is optional.The action defaults to search for the dependency file (
package-lock.json,npm-shrinkwrap.jsonoryarn.lock) in the repository root, and uses its hash as a part of the cache key. Usecache-dependency-pathfor cases when multiple dependency files are used, or they are located in different subdirectories.Note: The action does not cache
node_modulesSee the examples of using cache for
yarn/pnpmandcache-dependency-pathinput in the Advanced usage guide.Caching npm dependencies:
Caching npm dependencies in monorepos:
Caching for npm dependencies is automatically enabled when your
package.jsoncontains eitherdevEngines.packageManagerfield or top-levelpackageManagerfield set tonpm, and no explicit cache input is provided.This behavior is controlled by the
package-manager-cacheinput, which defaults totrue. To turn off automatic caching, setpackage-manager-cachetofalse.Matrix Testing
Using
setup-nodeon GHESsetup-nodecomes pre-installed on the appliance with GHES if Actions is enabled. When dynamically downloading Nodejs distributions,setup-nodedownloads distributions fromactions/node-versionson github.com (outside of the appliance). These calls toactions/node-versionsare made via unauthenticated requests, which are limited to 60 requests per hour per IP. If more requests are made within the time frame, then you will start to see rate-limit errors during downloading that looks like:##[error]API rate limit exceeded for.... After that error the action will try to download versions directly from the official site, but it also can have rate limit so it’s better to put token.To get a higher rate limit, you can generate a personal access token on github.com and pass it as the
tokeninput for the action:If the runner is not able to access github.com, any Nodejs versions requested during a workflow run must come from the runner’s tool cache. See “Setting up the tool cache on self-hosted runners without internet access“ for more information.
Advanced usage
Recommended permissions
When using the
setup-nodeaction in your GitHub Actions workflow, it is recommended to set the following permissions to ensure proper functionality:License
The scripts and documentation in this project are released under the MIT License
Contributions
Contributions are welcome! See Contributor’s Guide
Code of Conduct