renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 8s
ci / lint-actionlint (push) Successful in 5s
ci / lint-shellcheck (push) Successful in 14s
ci / lint-prettier (push) Successful in 15s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 9s
ci / lint-dockerfiles (push) Successful in 7s
ci / validate (push) Successful in 6s
ci / build (push) Skipped
ci / lint-compose (pull_request) Successful in 11s
ci / lint-actionlint (pull_request) Successful in 7s
ci / lint-shellcheck (pull_request) Successful in 12s
ci / lint-prettier (pull_request) Successful in 14s
ci / lint-ruff (pull_request) Successful in 5s
ci / lint-yaml (pull_request) Successful in 11s
ci / lint-dockerfiles (pull_request) Successful in 6s
ci / validate (pull_request) Successful in 6s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 8s
37 lines
1.8 KiB
Bash
37 lines
1.8 KiB
Bash
# Pinned versions of the CI tools installed by install-ci-tools.sh.
|
|
# Renovate keeps these up to date (see customManagers in renovate/renovate.json).
|
|
#
|
|
# Every version here except NODE_VERSION matches what was already installed on
|
|
# the runner, so pinning them changes what CI does not at all. It changes what
|
|
# CI does when the runner is rebuilt with something else: today
|
|
# install-ci-tools.sh finds the pinned version already on PATH and installs
|
|
# nothing, and a runner that drifts gets the pinned one installed over it.
|
|
#
|
|
# The renovate image version is NOT pinned here: renovate/k8s/cronjob.yaml is the
|
|
# single source of truth and the workflows read the tag from it, so there is
|
|
# nothing to drift.
|
|
ACTIONLINT_VERSION="1.7.7"
|
|
SHELLCHECK_VERSION="0.11.0"
|
|
KUBECONFORM_VERSION="0.8.0"
|
|
PRETTIER_VERSION="3.8.1"
|
|
RUFF_VERSION="0.16.8"
|
|
YAMLLINT_VERSION="1.38.0"
|
|
HADOLINT_VERSION="2.14.0"
|
|
# pip-audit reads the advisory database over the network, so a floating version
|
|
# would make the same commit report different things on different days. Pin it
|
|
# like the rest: the advisories themselves are the moving part, not the tool.
|
|
PIP_AUDIT_VERSION="2.10.1"
|
|
# uv builds the throwaway venv the pytest job runs in, and unpacks the PyPI
|
|
# wheels for ruff, yamllint and pip-audit.
|
|
UV_VERSION="0.12.17"
|
|
# node runs `npm ci` for the frontend tests and the npm audit, and it is the one
|
|
# pin here that does NOT come from the runner: the runner's system node is a
|
|
# rolling Arch package (it was node 26 with no npm at all when this was pinned),
|
|
# and the panel image is node:22-alpine. Pinned to the image's major on purpose,
|
|
# so the tree that gets tested is the tree that gets built. Renovate keeps this
|
|
# in step with the Dockerfile's node: tag via the "node runtime" group.
|
|
NODE_VERSION="22.23.3"
|
|
|
|
# Secret-reference regression tests parse rendered Kubernetes objects.
|
|
JQ_VERSION="1.8.1"
|