Skip to content

ci: add zizmor workflow and harden actions #142

ci: add zizmor workflow and harden actions

ci: add zizmor workflow and harden actions #142

Workflow file for this run

name: build
on:
push:
branches:
- main
pull_request:
branches:
- main
release:
types:
- released
workflow_dispatch: {}
permissions:
contents: read
concurrency:
group: '${{ github.workflow }} @ ${{ github.event.pull_request.head.label || github.head_ref || github.ref }}'
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
env:
# See https://github.com/nodejs/release#release-schedule
# Node.js v20 EOL = 2026-04-30. v22 EOL = 2027-04-30. v23 EOL = 2025-06-01. v24 EOL = 2028-04-30. v25 EOL = 2026-06-01.
# Node.js 20-24 can build with GCC 10 (bullseye)
NODE_BUILD_CMD_LEGACY: npx --no-install prebuild -r node -t 20.0.0 -t 22.0.0 -t 23.0.0 -t 24.0.0 --include-regex '_sqlite3'
# Node.js 25+ requires GCC 11+ for <source_location> header (bookworm)
NODE_BUILD_CMD_MODERN: npx --no-install prebuild -r node -t 25.0.0 --include-regex '_sqlite3'
NODE_IMAGE_ALPINE: node:20-alpine@sha256:fb4cd12c85ee03686f6af5362a0b0d56d50c58a04632e6c0fb8363f609372293
NODE_IMAGE_BOOKWORM: node:20-bookworm@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
NODE_IMAGE_BULLSEYE: node:20-bullseye@sha256:c0122351f25f04facee976f9db7214789eabadb489f4e4aea9cd00a0d6af77c4
jobs:
test:
strategy:
fail-fast: false
matrix:
os:
- ubuntu-22.04
- macos-15
- macos-15-intel
- windows-2022
node:
- 20
- 22
- 23
- 24
- 25
name: Testing Node ${{ matrix.node }} on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
with:
node-version: ${{ matrix.node }}
package-manager-cache: false
- if: ${{ startsWith(matrix.os, 'windows') }}
run: pip.exe install setuptools
- if: ${{ startsWith(matrix.os, 'macos') }}
run: brew install python-setuptools
- if: ${{ !startsWith(matrix.os, 'windows') && !startsWith(matrix.os, 'macos') }}
run: python3 -m pip install setuptools
- if: ${{ startsWith(matrix.os, 'ubuntu') && matrix.node < 25 }}
run: |
sudo apt update
sudo apt install -y gcc-10 g++-10 libreadline-dev libncurses5-dev
sudo update-alternatives --install /usr/bin/gcc gcc /usr/bin/gcc-10 100 --slave /usr/bin/g++ g++ /usr/bin/g++-10 --slave /usr/bin/gcov gcov /usr/bin/gcov-10
- if: ${{ startsWith(matrix.os, 'ubuntu') && matrix.node >= 25 }}
run: |
sudo apt update
sudo apt install -y gcc-11 g++-11 libreadline-dev libncurses5-dev
sudo update-alternatives --install /usr/bin/gcc gcc /usr/bin/gcc-11 100 --slave /usr/bin/g++ g++ /usr/bin/g++-11 --slave /usr/bin/gcov gcov /usr/bin/gcov-11
- run: npm install --ignore-scripts
- run: npm run build-debug
- run: npm test
- run: npm run build-release
- name: Test shell wrapper (Windows)
if: ${{ startsWith(matrix.os, 'windows') }}
shell: powershell
run: |
echo "SELECT 'wrapper test';" | node shell.js
node shell.js --version
- name: Test shell wrapper (Unix)
if: ${{ !startsWith(matrix.os, 'windows') }}
shell: bash
run: |
echo "SELECT 'wrapper test';" | node shell.js
node shell.js --version
test-bun:
strategy:
matrix:
os:
- ubuntu-22.04
- macos-15
- macos-15-intel
bun:
- 1.3.5
name: Testing Bun ${{ matrix.bun }} on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: ${{ matrix.bun }}
no-cache: true
- if: ${{ startsWith(matrix.os, 'macos') }}
run: brew install python-setuptools
- if: ${{ !startsWith(matrix.os, 'macos') }}
run: python3 -m pip install setuptools
- if: ${{ startsWith(matrix.os, 'ubuntu') }}
run: |
sudo apt update
sudo apt install -y gcc-10 g++-10 libreadline-dev libncurses5-dev
sudo update-alternatives --install /usr/bin/gcc gcc /usr/bin/gcc-10 100 --slave /usr/bin/g++ g++ /usr/bin/g++-10 --slave /usr/bin/gcov gcov /usr/bin/gcov-10
- run: bun install --ignore-scripts
- run: bun run build-debug
- run: bun run test
- run: bun run build-release
- name: Test shell wrapper (Windows)
if: ${{ startsWith(matrix.os, 'windows') }}
shell: powershell
run: |
echo "SELECT 'wrapper test';" | bun shell.js
bun shell.js --version
- name: Test shell wrapper (Unix)
if: ${{ !startsWith(matrix.os, 'windows') }}
shell: bash
run: |
echo "SELECT 'wrapper test';" | bun shell.js
bun shell.js --version
publish:
if: ${{ github.event_name == 'release' }}
name: Publishing to NPM
runs-on: ubuntu-22.04
permissions:
id-token: write # Required for OIDC trusted publishing
contents: read
needs:
- prebuild
- prebuild-alpine
- prebuild-alpine-arm
- prebuild-linux-x64
- prebuild-linux-arm
- prebuild-linux-x64-node-modern
- prebuild-linux-arm-node-modern
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
with:
node-version: 20
registry-url: https://registry.npmjs.org
package-manager-cache: false
- name: Upgrade npm for OIDC support
run: npm install -g npm@latest
- run: npm publish --provenance
prebuild:
if: ${{ github.event_name == 'release' }}
strategy:
fail-fast: false
matrix:
os:
- macos-15
- macos-15-intel
- windows-2022
name: Prebuild on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
needs: test
permissions:
contents: write # Required to upload prebuild artifacts to the GitHub release.
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
with:
node-version: 20
package-manager-cache: false
- if: ${{ startsWith(matrix.os, 'windows') }}
run: pip.exe install setuptools
- if: ${{ startsWith(matrix.os, 'macos') }}
run: brew install python-setuptools
- run: npm install --ignore-scripts
- name: Prebuild Node 20-24
shell: bash
env:
GH_TOKEN: ${{ github.token }}
run: $NODE_BUILD_CMD_LEGACY -u "$GH_TOKEN"
- name: Prebuild Node 25+
shell: bash
env:
GH_TOKEN: ${{ github.token }}
run: $NODE_BUILD_CMD_MODERN -u "$GH_TOKEN"
- if: matrix.os == 'windows-2022'
shell: bash
env:
GH_TOKEN: ${{ github.token }}
run: |
$NODE_BUILD_CMD_LEGACY --arch ia32 -u "$GH_TOKEN"
$NODE_BUILD_CMD_MODERN --arch ia32 -u "$GH_TOKEN"
$NODE_BUILD_CMD_LEGACY --arch arm64 -u "$GH_TOKEN"
$NODE_BUILD_CMD_MODERN --arch arm64 -u "$GH_TOKEN"
prebuild-linux-x64:
if: ${{ github.event_name == 'release' }}
name: Prebuild on Linux x64
runs-on: ubuntu-latest
container: node:20-bullseye@sha256:c0122351f25f04facee976f9db7214789eabadb489f4e4aea9cd00a0d6af77c4
needs: test
permissions:
contents: write # Required to upload prebuild artifacts to the GitHub release.
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- run: npm install --ignore-scripts
- name: Prebuild Node 20-24
env:
GH_TOKEN: ${{ github.token }}
run: $NODE_BUILD_CMD_LEGACY -u "$GH_TOKEN"
prebuild-linux-x64-node-modern:
if: ${{ github.event_name == 'release' }}
name: Prebuild on Linux x64 (Node 25+)
runs-on: ubuntu-latest
container: node:20-bookworm@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
needs: test
permissions:
contents: write # Required to upload prebuild artifacts to the GitHub release.
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- run: npm install --ignore-scripts
- name: Prebuild Node 25+
env:
GH_TOKEN: ${{ github.token }}
run: $NODE_BUILD_CMD_MODERN -u "$GH_TOKEN"
prebuild-alpine:
if: ${{ github.event_name == 'release' }}
name: Prebuild on alpine
runs-on: ubuntu-latest
container: node:20-alpine@sha256:fb4cd12c85ee03686f6af5362a0b0d56d50c58a04632e6c0fb8363f609372293
needs: test
permissions:
contents: write # Required to upload prebuild artifacts to the GitHub release.
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- run: apk add build-base git python3 py3-setuptools libstdc++ readline-dev ncurses-dev --update-cache
- run: npm install --ignore-scripts
- name: Prebuild Node 20-24
env:
GH_TOKEN: ${{ github.token }}
run: $NODE_BUILD_CMD_LEGACY -u "$GH_TOKEN"
- name: Prebuild Node 25+
env:
GH_TOKEN: ${{ github.token }}
run: $NODE_BUILD_CMD_MODERN -u "$GH_TOKEN"
prebuild-alpine-arm:
if: ${{ github.event_name == 'release' }}
strategy:
fail-fast: false
matrix:
arch:
- arm/v7
- arm64
name: Prebuild on alpine (${{ matrix.arch }})
runs-on: ubuntu-latest
needs: test
permissions:
contents: write # Required to upload prebuild artifacts to the GitHub release.
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
- env:
ARCH: ${{ matrix.arch }}
GH_TOKEN: ${{ github.token }}
run: |
docker run --rm -e GH_TOKEN -e NODE_BUILD_CMD_LEGACY -e NODE_BUILD_CMD_MODERN -v "$(pwd):/tmp/project" --entrypoint /bin/sh --platform "linux/$ARCH" "$NODE_IMAGE_ALPINE" -c "\
apk add build-base git python3 py3-setuptools libstdc++ readline-dev ncurses-dev --update-cache && \
cd /tmp/project && \
npm install --ignore-scripts && \
\$NODE_BUILD_CMD_LEGACY -u \"\$GH_TOKEN\" && \
\$NODE_BUILD_CMD_MODERN -u \"\$GH_TOKEN\""
prebuild-linux-arm:
if: ${{ github.event_name == 'release' }}
strategy:
fail-fast: false
matrix:
arch:
- arm/v7
- arm64
name: Prebuild on Linux (${{ matrix.arch }})
runs-on: ubuntu-latest
needs: test
permissions:
contents: write # Required to upload prebuild artifacts to the GitHub release.
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
- env:
ARCH: ${{ matrix.arch }}
GH_TOKEN: ${{ github.token }}
run: |
docker run --rm -e GH_TOKEN -e NODE_BUILD_CMD_LEGACY -v "$(pwd):/tmp/project" --entrypoint /bin/sh --platform "linux/$ARCH" "$NODE_IMAGE_BULLSEYE" -c "\
cd /tmp/project && \
npm install --ignore-scripts && \
\$NODE_BUILD_CMD_LEGACY -u \"\$GH_TOKEN\""
prebuild-linux-arm-node-modern:
if: ${{ github.event_name == 'release' }}
strategy:
fail-fast: false
matrix:
arch:
- arm/v7
- arm64
name: Prebuild on Linux (${{ matrix.arch }}) (Node 25+)
runs-on: ubuntu-latest
needs: test
permissions:
contents: write # Required to upload prebuild artifacts to the GitHub release.
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
- env:
ARCH: ${{ matrix.arch }}
GH_TOKEN: ${{ github.token }}
run: |
docker run --rm -e GH_TOKEN -e NODE_BUILD_CMD_MODERN -v "$(pwd):/tmp/project" --entrypoint /bin/sh --platform "linux/$ARCH" "$NODE_IMAGE_BOOKWORM" -c "\
cd /tmp/project && \
npm install --ignore-scripts && \
\$NODE_BUILD_CMD_MODERN -u \"\$GH_TOKEN\""