# Pinned versions of the CI tools installed by install-ci-tools.sh. # Renovate keeps these up to date (see customManagers in renovate/renovate.json). # # Every version here except NODE_VERSION matches what was already installed on # the runner, so pinning them changes what CI does not at all. It changes what # CI does when the runner is rebuilt with something else: today # install-ci-tools.sh finds the pinned version already on PATH and installs # nothing, and a runner that drifts gets the pinned one installed over it. # # The renovate image version is NOT pinned here: renovate/k8s/cronjob.yaml is the # single source of truth and the workflows read the tag from it, so there is # nothing to drift. ACTIONLINT_VERSION="1.7.7" SHELLCHECK_VERSION="0.11.0" KUBECONFORM_VERSION="0.8.0" PRETTIER_VERSION="3.8.1" RUFF_VERSION="0.16.8" YAMLLINT_VERSION="1.38.0" HADOLINT_VERSION="2.14.0" # pip-audit reads the advisory database over the network, so a floating version # would make the same commit report different things on different days. Pin it # like the rest: the advisories themselves are the moving part, not the tool. PIP_AUDIT_VERSION="2.10.1" # uv builds the throwaway venv the pytest job runs in, and unpacks the PyPI # wheels for ruff, yamllint and pip-audit. UV_VERSION="0.12.17" # node runs `npm ci` for the frontend tests and the npm audit, and it is the one # pin here that does NOT come from the runner: the runner's system node is a # rolling Arch package (it was node 26 with no npm at all when this was pinned), # and the panel image is node:22-alpine. Pinned to the image's major on purpose, # so the tree that gets tested is the tree that gets built. Renovate keeps this # in step with the Dockerfile's node: tag via the "node runtime" group. NODE_VERSION="22.23.3"