62 Commits

Author SHA1 Message Date
renovate[bot]
e8b98b1f5b chore(actions): update ivuorinen/actions action (v2026.03.10 → v2026.03.11)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-12 09:20:01 +00:00
semantic-release-bot
57e84e42d7 chore(release): 1.0.8 [skip ci]
## [1.0.8](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.7...v1.0.8) (2026-03-12)
2026-03-12 09:11:24 +00:00
dependabot[bot]
5790c57f1e chore(deps): bump tar from 7.5.10 to 7.5.11 (#127)
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.10 to 7.5.11.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.10...v7.5.11)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.11
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-12 11:08:32 +02:00
renovate[bot]
509dad2a17 chore(actions): update ivuorinen/actions action to v2026.03.10 (#126)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-11 01:36:43 +02:00
6b5f1ab770 ci: migrate CodeQL to ivuorinen/actions/codeql-analysis (#125)
* ci: migrate codeql to composable workflow

* fix: correct codeql workflow permissions, cron, and action ref

- Set root-level permissions to {}
- Add job-level permissions (actions, contents, packages, security-events)
- Pin action ref to commit hash with version comment
- Fix mangled cron schedule
- Clean up workflow structure

* fix: correct codeql workflow language, queries, permissions, and action ref

- Use 'javascript' instead of 'javascript-typescript' for CodeQL language
- Add queries: security-and-quality parameter
- Set root-level permissions to {}
- Add job-level permissions (actions, contents, packages, security-events)
- Pin action ref to commit hash with version comment
- Fix mangled cron schedule
2026-03-07 17:48:55 +02:00
semantic-release-bot
e12e70bc3d chore(release): 1.0.7 [skip ci]
## [1.0.7](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.6...v1.0.7) (2026-03-07)
2026-03-07 04:47:33 +00:00
renovate[bot]
b3920744ac chore(deps): update github/codeql-action action (v4.32.5 → v4.32.6) (#124)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-07 04:44:56 +00:00
semantic-release-bot
23690b3169 chore(release): 1.0.6 [skip ci]
## [1.0.6](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.5...v1.0.6) (2026-03-05)
2026-03-05 20:21:47 +00:00
renovate[bot]
908726efad chore(deps): update actions/setup-node action (v6.2.0 → v6.3.0) (#122) 2026-03-05 22:19:22 +02:00
renovate[bot]
6ddd1d616b chore(deps): lock file maintenance (#123) 2026-03-05 22:17:31 +02:00
semantic-release-bot
8330da9f1d chore(release): 1.0.5 [skip ci]
## [1.0.5](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.4...v1.0.5) (2026-03-05)
2026-03-05 18:42:53 +00:00
dependabot[bot]
314c203726 chore(deps): bump tar from 7.5.9 to 7.5.10 (#121) 2026-03-05 20:30:25 +02:00
semantic-release-bot
fe787499dd chore(release): 1.0.4 [skip ci]
## [1.0.4](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.3...v1.0.4) (2026-03-05)
2026-03-05 14:36:16 +00:00
renovate[bot]
fd7f03713e chore(deps): update pre-commit hook igorshubovych/markdownlint-cli (v0.47.0 → v0.48.0) (#120)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-05 14:33:52 +00:00
semantic-release-bot
178ff5638b chore(release): 1.0.3 [skip ci]
## [1.0.3](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.2...v1.0.3) (2026-03-04)
2026-03-04 09:22:46 +00:00
renovate[bot]
9b2759f7cf chore(deps): update ivuorinen/actions action (v2026.02.24 → v2026.03.02) (#119)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-04 11:20:20 +02:00
semantic-release-bot
3d6f082473 chore(release): 1.0.2 [skip ci]
## [1.0.2](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.1...v1.0.2) (2026-03-04)
2026-03-04 05:29:30 +00:00
renovate[bot]
39ccdd13d7 chore(deps): update github/codeql-action action (v4.32.4 → v4.32.5) (#118)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-04 05:27:18 +00:00
semantic-release-bot
ad205051ca chore(release): 1.0.1 [skip ci]
## [1.0.1](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.0...v1.0.1) (2026-03-02)
2026-03-02 01:35:42 +00:00
renovate[bot]
d0d038ef7d chore(deps): lock file maintenance (#117)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-03-02 03:33:34 +02:00
dependabot[bot]
8d4d388011 chore(deps): bump minimatch from 10.2.2 to 10.2.4 (#116) 2026-03-01 11:07:51 +02:00
renovate[bot]
c41f2f1bc9 chore(deps): update node.js (v24.13.1 → v24.14.0) (#115)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-26 04:58:41 +00:00
renovate[bot]
7f2d3db01f chore(deps): update ivuorinen/actions action (v2026.02.18 → v2026.02.24) (#114)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-26 03:03:38 +00:00
renovate[bot]
74872b399e chore(deps): lock file maintenance (#113) 2026-02-23 21:42:19 +02:00
renovate[bot]
c62d938088 chore(deps): update github/codeql-action action (v4.32.3 → v4.32.4) (#112)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-22 04:39:58 +00:00
renovate[bot]
ff9cc9a5a4 chore(deps): update ivuorinen/actions action (v2026.02.10 → v2026.02.18) (#111)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-20 09:30:58 +00:00
renovate[bot]
4fdc80b738 chore(deps): lock file maintenance (#109) 2026-02-17 19:21:36 +02:00
renovate[bot]
b916a106f5 chore(deps): update pre-commit hook rhysd/actionlint (v1.7.10 → v1.7.11) (#110)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-16 12:42:04 +00:00
renovate[bot]
5059ebf731 chore(deps): update github/codeql-action action (v4.32.2 → v4.32.3) (#108)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-15 05:11:48 +00:00
renovate[bot]
9ff95ff491 chore(deps): update ivuorinen/actions action (v2026.02.03 → v2026.02.10) (#107)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-12 09:33:52 +00:00
renovate[bot]
797fe3e1f7 chore(deps): update node.js (v24.13.0 → v24.13.1) (#106)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-12 05:53:48 +00:00
renovate[bot]
1d4b50e6a0 chore(deps): update simek/yarn-lock-changes action (v0.14.0 → v0.14.1) (#105)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-09 05:37:55 +00:00
renovate[bot]
6a85830325 chore(deps): update github/codeql-action action (v4.32.1 → v4.32.2) (#104)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-07 05:03:54 +00:00
renovate[bot]
f319515dab chore(deps): update ivuorinen/actions action (v2026.01.21 → v2026.02.03) (#103)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-05 05:48:38 +00:00
renovate[bot]
ff62586ffd chore(deps): update github/codeql-action action (v4.32.0 → v4.32.1) (#102)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-04 00:30:58 +02:00
renovate[bot]
6528aed35f chore(deps): update simek/yarn-lock-changes action (v0.12.2 → v0.14.0) (#101)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-02-01 18:00:03 +00:00
renovate[bot]
b195d0268a chore(deps): update actions/cache action (v5.0.2 → v5.0.3) (#100)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-31 05:44:02 +00:00
dependabot[bot]
bba9f9723d chore(deps): bump tar from 7.5.6 to 7.5.7 (#99)
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.6 to 7.5.7.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.6...v7.5.7)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-29 20:37:26 +02:00
dependabot[bot]
9bd18ced07 chore(deps): bump lodash from 4.17.21 to 4.17.23 (#97)
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.17.23
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-27 14:27:55 +02:00
dependabot[bot]
f8773cc7cf chore(deps): bump js-yaml from 4.1.0 to 4.1.1 (#96)
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.0 to 4.1.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.0...4.1.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.1.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-27 14:21:12 +02:00
dependabot[bot]
1216ff662e chore(deps): bump lodash-es from 4.17.21 to 4.17.23 (#95)
Bumps [lodash-es](https://github.com/lodash/lodash) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23)

---
updated-dependencies:
- dependency-name: lodash-es
  dependency-version: 4.17.23
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-27 14:20:40 +02:00
renovate[bot]
47d9108464 chore(deps): update github/codeql-action action (v4.31.11 → v4.32.0) (#98)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-27 14:19:55 +02:00
dependabot[bot]
570357948d chore(deps): bump tar from 7.5.2 to 7.5.6 (#94)
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.2 to 7.5.6.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.2...v7.5.6)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-27 14:19:07 +02:00
renovate[bot]
e9f820b8c2 chore(deps): update github/codeql-action action (v4.31.10 → v4.31.11) (#93)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-25 21:39:49 +02:00
renovate[bot]
5ded8efb6d chore(deps): update actions/checkout action (v6.0.1 → v6.0.2) (#92)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-24 12:56:45 +00:00
renovate[bot]
a3ff88290a chore(deps): update ivuorinen/actions action (v2026.01.13 → v2026.01.21) (#91)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-23 06:16:28 +00:00
renovate[bot]
1c05de370d chore(deps): update actions/cache action (v5.0.1 → v5.0.2) (#90)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-18 11:53:02 +02:00
renovate[bot]
cf75636367 chore(deps): update actions/setup-node action (v6.1.0 → v6.2.0) (#89)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-17 04:58:11 +00:00
renovate[bot]
97141a58d6 chore(deps): update pre-commit hook adrienverge/yamllint (v1.37.1 → v1.38.0) (#88) 2026-01-15 21:25:28 +02:00
renovate[bot]
1f6bda714d chore(deps): update node.js (v24.12.0 → v24.13.0) (#87)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-15 17:56:10 +00:00
renovate[bot]
1862133888 chore(deps): update ivuorinen/actions action (v2026.01.09 → v2026.01.13) (#86)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-15 12:34:22 +00:00
renovate[bot]
37241789b1 chore(deps): update github/codeql-action action (v4.31.9 → v4.31.10) (#85)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-14 05:01:41 +00:00
renovate[bot]
68915595de chore(deps): update ivuorinen/actions action (v2026.01.06 → v2026.01.09) (#84)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-11 05:01:47 +00:00
renovate[bot]
38fc0d8b8f chore(deps)!: update ivuorinen/actions (v2025.12.31 → v2026.01.06) (#82)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-07 15:58:00 +02:00
renovate[bot]
8c168880b0 chore(deps): update ivuorinen/actions action (v2025.12.05 → v2025.12.31) (#83)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-02 17:32:48 +00:00
renovate[bot]
fd1fbdbdb6 chore(deps): update pre-commit hook rhysd/actionlint (v1.7.9 → v1.7.10) (#81)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-01-01 09:45:48 +00:00
renovate[bot]
4124fd4d8a chore(deps): update github/codeql-action action (v4.31.8 → v4.31.9) (#80)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-18 05:05:31 +00:00
renovate[bot]
7e1658c94e chore(deps): update pre-commit hook igorshubovych/markdownlint-cli (v0.46.0 → v0.47.0) (#79)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-14 13:13:21 +00:00
renovate[bot]
dee143f801 chore(deps): update actions/cache action (v5.0.0 → v5.0.1) (#78)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-14 09:12:05 +00:00
renovate[bot]
b5fed65901 chore(deps): update github/codeql-action action (v4.31.7 → v4.31.8) (#73)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-13 02:51:37 +00:00
renovate[bot]
d3917bc7f3 chore(deps)!: update actions/cache (v4.3.0 → v5.0.0) (#77)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-12 12:13:13 +02:00
renovate[bot]
4bc6e86161 chore(deps): update node.js (v24.11.1 → v24.12.0) (#76)
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-12-12 03:02:36 +00:00
10 changed files with 570 additions and 841 deletions

View File

@@ -1,17 +1,6 @@
---
# yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL Advanced"
name: "CodeQL"
on:
push:
@@ -20,84 +9,26 @@ on:
branches: ["main"]
schedule:
- cron: "22 8 * * 0"
merge_group:
permissions: {}
jobs:
analyze:
name: Analyze (${{ matrix.language }})
# Runner size impacts CodeQL analysis time. To learn more, please see:
# - https://gh.io/recommended-hardware-resources-for-running-codeql
# - https://gh.io/supported-runners-and-hardware-resources
# - https://gh.io/using-larger-runners (GitHub.com only)
# Consider using larger runners or machines with greater resources for possible analysis time improvements.
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
name: Analyze
runs-on: ubuntu-latest
permissions:
# required for all workflows
security-events: write
# required to fetch internal or private CodeQL packs
packages: read
# only required for workflows in private repositories
actions: read
contents: read
packages: read
security-events: write
strategy:
fail-fast: false
matrix:
include:
- language: actions
build-mode: none
- language: javascript-typescript
build-mode: none
# CodeQL supports the following values keywords for 'language':
# 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'swift'
# Use `c-cpp` to analyze code written in C, C++ or both
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
language: ["actions", "javascript"]
steps:
- name: Checkout repository
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
# Add any setup steps before running the `github/codeql-action/init` action.
# This includes steps like installing compilers or runtimes (`actions/setup-node`
# or others). This is typically only required for manual builds.
# - name: Setup runtime (example)
# uses: actions/setup-example@v1
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
- name: CodeQL Analysis
uses: ivuorinen/actions/codeql-analysis@7f6a23b59316795c4b3cb3b3b28dd53e53655a33 # v2026.03.11
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.
# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
# queries: security-extended,security-and-quality
# If the analyze step fails for one of the languages you are analyzing with
# "We were unable to automatically build your code", modify the matrix above
# to set the build mode to "manual" for that language. Then modify this step
# to build your code.
# Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
- if: matrix.build-mode == 'manual'
shell: bash
run: |
echo 'If you are using a "manual" build mode for one or more of the' \
'languages you are analyzing, replace this with the commands to build' \
'your code, for example:'
echo ' make bootstrap'
echo ' make release'
exit 1
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@cf1bb45a277cb3c205638b2cd5c984db1c46a412 # v4.31.7
with:
category: "/language:${{matrix.language}}"
language: ${{ matrix.language }}
queries: security-and-quality

View File

@@ -30,7 +30,7 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
token: ${{ secrets.GITHUB_TOKEN }}
@@ -39,7 +39,7 @@ jobs:
run: npm install -g corepack --force && corepack enable
- name: Yarn Lock Changes
uses: Simek/yarn-lock-changes@61d1a0595070b79c1abdc8e1e5a5f5d98b18918c # v0.12.2
uses: Simek/yarn-lock-changes@59f47ee499424d2c2437c5aebf863b5c6d50a5bc # v0.14.1
with:
token: ${{ secrets.GITHUB_TOKEN }}
env:
@@ -48,7 +48,7 @@ jobs:
- name: Run PR Lint
# https://github.com/ivuorinen/actions
uses: ivuorinen/actions/pr-lint@a52399cf74eac2b0963591ab2c6c8eb0f7f50b2d # v2025.12.05
uses: ivuorinen/actions/pr-lint@7f6a23b59316795c4b3cb3b3b28dd53e53655a33 # v2026.03.11
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}

View File

@@ -26,7 +26,7 @@ jobs:
steps:
- name: Run PR Lint
# https://github.com/ivuorinen/actions
uses: ivuorinen/actions/pr-lint@a52399cf74eac2b0963591ab2c6c8eb0f7f50b2d # v2025.12.05
uses: ivuorinen/actions/pr-lint@7f6a23b59316795c4b3cb3b3b28dd53e53655a33 # v2026.03.11
publish:
name: Publish
@@ -41,12 +41,12 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- name: Setup Node.js Environment
uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
with:
always-auth: true
node-version-file: ".nvmrc"
@@ -58,7 +58,7 @@ jobs:
run: npm install -g corepack --force && corepack enable
- name: Cache Node Modules
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
id: cache
with:
path: node_modules

View File

@@ -23,4 +23,4 @@ jobs:
issues: write
pull-requests: write
steps:
- uses: ivuorinen/actions/stale@a52399cf74eac2b0963591ab2c6c8eb0f7f50b2d # v2025.12.05
- uses: ivuorinen/actions/stale@7f6a23b59316795c4b3cb3b3b28dd53e53655a33 # v2026.03.11

View File

@@ -34,8 +34,8 @@ jobs:
steps:
- name: ⤵️ Checkout Repository
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
token: ${{ secrets.GITHUB_TOKEN }}
- name: ⤵️ Sync Latest Labels Definitions
uses: ivuorinen/actions/sync-labels@a52399cf74eac2b0963591ab2c6c8eb0f7f50b2d # v2025.12.05
uses: ivuorinen/actions/sync-labels@7f6a23b59316795c4b3cb3b3b28dd53e53655a33 # v2026.03.11

2
.nvmrc
View File

@@ -1 +1 @@
24.11.1
24.14.0

View File

@@ -19,18 +19,18 @@ repos:
args: [--autofix, --no-sort-keys]
- repo: https://github.com/igorshubovych/markdownlint-cli
rev: v0.46.0
rev: v0.48.0
hooks:
- id: markdownlint
args: [-c, .markdownlint.json, --fix]
- repo: https://github.com/adrienverge/yamllint
rev: v1.37.1
rev: v1.38.0
hooks:
- id: yamllint
- repo: https://github.com/rhysd/actionlint
rev: v1.7.9
rev: v1.7.11
hooks:
- id: actionlint
args: ["-shellcheck="]

View File

@@ -3,6 +3,22 @@
All notable changes to this project will be documented in this file. See
[Conventional Commits](https://conventionalcommits.org) for commit guidelines.
## [1.0.8](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.7...v1.0.8) (2026-03-12)
## [1.0.7](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.6...v1.0.7) (2026-03-07)
## [1.0.6](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.5...v1.0.6) (2026-03-05)
## [1.0.5](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.4...v1.0.5) (2026-03-05)
## [1.0.4](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.3...v1.0.4) (2026-03-05)
## [1.0.3](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.2...v1.0.3) (2026-03-04)
## [1.0.2](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.1...v1.0.2) (2026-03-04)
## [1.0.1](https://github.com/ivuorinen/base-configs-commitlint/compare/v1.0.0...v1.0.1) (2026-03-02)
# 1.0.0 (2025-12-06)

View File

@@ -1,6 +1,6 @@
{
"name": "@ivuorinen/commitlint-config",
"version": "1.0.0",
"version": "1.0.8",
"type": "module",
"description": "ivuorinen's shareable configuration for commitlint.",
"author": {

1270
yarn.lock

File diff suppressed because it is too large Load Diff