build(deps): bump astro from 6.4.6 to 7.1.0 in /docs #28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Docs | |
| on: | |
| push: | |
| branches: [main] | |
| paths: | |
| - 'docs/**' | |
| - 'CHANGELOG.md' | |
| - '.github/workflows/docs.yml' | |
| pull_request: | |
| paths: | |
| - 'docs/**' | |
| - 'CHANGELOG.md' | |
| - '.github/workflows/docs.yml' | |
| workflow_dispatch: | |
| # Permissions are declared per-job rather than here at the top so | |
| # each job gets only what it needs: `build` just reads the repo, | |
| # and only `deploy` touches Pages + the OIDC token. | |
| # No workflow-level `concurrency:` — the two jobs need different | |
| # rules. A PR build only has to cancel its own superseded runs; the | |
| # Pages deploy needs a global lock (GitHub allows one live | |
| # deployment at a time) and must never be cancelled mid-flight. One | |
| # shared group can't express both, so each job declares its own. | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| # Superseded PR builds cancel; `main` builds (keyed on the | |
| # branch ref) run to completion so every push to main is | |
| # deployed. | |
| concurrency: | |
| group: docs-build-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| steps: | |
| # Actions pinned to a full commit SHA (mutable tags can be | |
| # repointed at malicious code); the `# vX.Y.Z` comment is | |
| # what Dependabot bumps. `persist-credentials: false` keeps | |
| # the token out of `.git/config` — the build never pushes. | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| with: | |
| persist-credentials: false | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6.0.9 | |
| with: | |
| version: 11 | |
| - name: Setup Node | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| with: | |
| node-version: 22 | |
| cache: pnpm | |
| cache-dependency-path: docs/pnpm-lock.yaml | |
| - name: Install dependencies | |
| working-directory: docs | |
| run: pnpm install --frozen-lockfile | |
| - name: Build site | |
| working-directory: docs | |
| run: pnpm build | |
| - name: Upload artifact | |
| uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 | |
| with: | |
| path: docs/dist | |
| deploy: | |
| # Deploy on pushes to main AND on manual workflow_dispatch runs. | |
| # The latter is the escape hatch for re-deploying after a failed | |
| # initial run (e.g. before GitHub Pages was enabled on the repo). | |
| # PR builds still gate-off because they target a fork-or-branch | |
| # build that shouldn't replace the live site. | |
| if: | | |
| (github.event_name == 'push' && github.ref == 'refs/heads/main') | |
| || github.event_name == 'workflow_dispatch' | |
| needs: build | |
| runs-on: ubuntu-latest | |
| permissions: | |
| pages: write | |
| id-token: write | |
| # GitHub Pages allows one live deployment at a time, so this | |
| # global `pages` group serialises deploys across all runs. | |
| # Never cancel one in flight — a half-applied deployment is | |
| # worse than a slow one. | |
| concurrency: | |
| group: pages | |
| cancel-in-progress: false | |
| environment: | |
| name: github-pages | |
| url: ${{ steps.deployment.outputs.page_url }} | |
| steps: | |
| - name: Deploy to GitHub Pages | |
| id: deployment | |
| uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0 |