Chore(deps): Bump browserslist from 4.28.0 to 4.28.9 #6821
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # GitHub Actions docs | |
| # https://help.github.com/en/articles/about-github-actions | |
| # https://help.github.com/en/articles/workflow-syntax-for-github-actions | |
| name: CI | |
| on: | |
| # Trigger the workflow on push or pull request, | |
| # but only for the master branch | |
| push: | |
| branches: | |
| - master | |
| pull_request: | |
| branches: | |
| - master | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| lint-typescript: | |
| name: Lint application code | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - &checkout_step | |
| name: Make checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Setup Node + Corepack + Yarn deps | |
| uses: ./.github/actions/setup-yarn | |
| - name: Run `yarn lint:ts` | |
| run: yarn lint:ts | |
| lint-scss: | |
| name: Lint application SCSS files | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - *checkout_step | |
| - name: Setup Node + Corepack + Yarn deps | |
| uses: ./.github/actions/setup-yarn | |
| - name: Run `yarn lint:scss` | |
| run: yarn lint:scss | |
| lint-documentation: | |
| name: Lint documentation files | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - *checkout_step | |
| - name: Setup Node + Corepack + Yarn deps | |
| uses: ./.github/actions/setup-yarn | |
| - name: Run `yarn lint:md` | |
| run: yarn lint:md | |
| check-translations: | |
| name: Check that translations are up-to-date | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - *checkout_step | |
| - name: Setup Node + Corepack + Yarn deps | |
| uses: ./.github/actions/setup-yarn | |
| - name: Run `yarn run extract-translations && git diff --exit-code` | |
| run: yarn run extract-translations && git diff --exit-code | |
| check-untranslated-text-tags: | |
| name: Check that there are no untranslated text tags | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - *checkout_step | |
| - name: Setup Node + Corepack + Yarn deps | |
| uses: ./.github/actions/setup-yarn | |
| - name: Run `yarn run check-translations` | |
| run: yarn run check-translations | |
| build: | |
| name: Build application Docker image | |
| runs-on: ubuntu-24.04 | |
| needs: | |
| - lint-typescript | |
| - lint-scss | |
| - lint-documentation | |
| - check-translations | |
| - check-untranslated-text-tags | |
| steps: | |
| - *checkout_step | |
| - name: Set tag var | |
| id: vars | |
| run: echo "DOCKER_TAG=$(echo ${GITHUB_REF} | sed -r 's/[\/()\.]+/_/g')-${GITHUB_SHA}" >> $GITHUB_OUTPUT | |
| - name: Build the Docker image | |
| run: docker build . --file Dockerfile --build-arg TARGET=production --tag angular-ngrx-frontend:${{ steps.vars.outputs.DOCKER_TAG }} | |
| - name: Run Trivy vulnerability scanner | |
| uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # 0.36.0 | |
| with: | |
| image-ref: 'angular-ngrx-frontend:${{ steps.vars.outputs.DOCKER_TAG }}' | |
| format: 'table' | |
| exit-code: '1' | |
| ignore-unfixed: true | |
| vuln-type: 'os,library' | |
| severity: 'CRITICAL,HIGH' |