From 3891d93c150cce4b7a21e2456bcf709e3e55ad89 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 01:18:16 -0300 Subject: [PATCH 1/6] feat: add reusable npm build workflow --- .github/workflows/npm-build.yml | 116 ++++++++++++++++++++++++++++++++ 1 file changed, 116 insertions(+) create mode 100644 .github/workflows/npm-build.yml diff --git a/.github/workflows/npm-build.yml b/.github/workflows/npm-build.yml new file mode 100644 index 0000000..8ecf04e --- /dev/null +++ b/.github/workflows/npm-build.yml @@ -0,0 +1,116 @@ +# SPDX-FileCopyrightText: 2021-2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors +# SPDX-License-Identifier: MIT + +name: Build Javascript + +on: + workflow_call: + +permissions: + contents: read + +concurrency: + group: node-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + +jobs: + changes: + runs-on: ubuntu-latest + permissions: + contents: read + pull-requests: read + outputs: + src: ${{ steps.changes.outputs.src }} + steps: + - name: Detect frontend changes + id: changes + uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 + continue-on-error: true + with: + filters: | + src: + - '.github/workflows/**' + - 'src/**' + - 'appinfo/info.xml' + - 'package.json' + - 'package-lock.json' + - 'tsconfig.json' + - '**.js' + - '**.ts' + - '**.vue' + + build: + runs-on: ubuntu-latest + needs: changes + if: needs.changes.outputs.src != 'false' + name: NPM build + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Read package.json node and npm engines version + id: versions + uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3 + with: + fallbackNode: '^24' + fallbackNpm: '^11.3' + + - name: Set up node ${{ steps.versions.outputs.nodeVersion }} + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: ${{ steps.versions.outputs.nodeVersion }} + + - name: Set up npm + env: + NPM_VERSION: ${{ steps.versions.outputs.npmVersion }} + run: npm install --global "npm@$NPM_VERSION" + + - name: Validate package-lock.json + run: | + npm install --global npm-package-lock-add-resolved@1.1.4 + npm-package-lock-add-resolved + git --no-pager diff --exit-code + + - name: Install dependencies and build + env: + CYPRESS_INSTALL_BINARY: 0 + PUPPETEER_SKIP_DOWNLOAD: true + run: | + npm ci + npm run build --if-present + + - name: Check build changes + run: | + if [ -n "$(git status --porcelain)" ]; then + echo 'Please recompile and commit the assets. See the "Show changes on failure" step for details.' + exit 1 + fi + + - name: Show changes on failure + if: failure() + run: | + git status + git --no-pager diff + exit 1 + + summary: + permissions: + contents: none + runs-on: ubuntu-latest + needs: + - changes + - build + if: always() + name: node + steps: + - name: Summary status + env: + CHANGED: ${{ needs.changes.outputs.src }} + BUILD_RESULT: ${{ needs.build.result }} + run: | + if [ "$CHANGED" != "false" ] && [ "$BUILD_RESULT" != "success" ]; then + exit 1 + fi From 1d4158112e3042e27c973eee744baaa1ec7f827b Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 01:20:01 -0300 Subject: [PATCH 2/6] feat: add npm build caller template --- workflow-templates/npm-build.yml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 workflow-templates/npm-build.yml diff --git a/workflow-templates/npm-build.yml b/workflow-templates/npm-build.yml new file mode 100644 index 0000000..d538778 --- /dev/null +++ b/workflow-templates/npm-build.yml @@ -0,0 +1,16 @@ +# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors +# SPDX-License-Identifier: AGPL-3.0-or-later + +# This workflow is published through the LibreCode organization catalog. +# Implementation: LibreCodeCoop/github-workflows + +name: Build Javascript + +on: pull_request + +permissions: + contents: read + +jobs: + npm-build: + uses: LibreCodeCoop/github-workflows/.github/workflows/npm-build.yml@3891d93c150cce4b7a21e2456bcf709e3e55ad89 From ec3a425e0681742ddc6919cbae5f2011ddaef769 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 01:20:03 -0300 Subject: [PATCH 3/6] feat: add npm build template metadata --- workflow-templates/npm-build.properties.json | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 workflow-templates/npm-build.properties.json diff --git a/workflow-templates/npm-build.properties.json b/workflow-templates/npm-build.properties.json new file mode 100644 index 0000000..4364d06 --- /dev/null +++ b/workflow-templates/npm-build.properties.json @@ -0,0 +1,11 @@ +{ + "name": "Frontend build", + "description": "Install frontend dependencies, validate the lockfile, build assets and check for uncommitted build changes.", + "iconName": "octicon package", + "categories": [ + "JavaScript" + ], + "filePatterns": [ + "^package.json$" + ] +} From e6d64377689d2271911c3919d615dde320f8d895 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 01:20:06 -0300 Subject: [PATCH 4/6] chore: license npm build template metadata --- workflow-templates/npm-build.properties.json.license | 2 ++ 1 file changed, 2 insertions(+) create mode 100644 workflow-templates/npm-build.properties.json.license diff --git a/workflow-templates/npm-build.properties.json.license b/workflow-templates/npm-build.properties.json.license new file mode 100644 index 0000000..1ce4e0c --- /dev/null +++ b/workflow-templates/npm-build.properties.json.license @@ -0,0 +1,2 @@ +SPDX-FileCopyrightText: 2026 LibreCode coop and contributors +SPDX-License-Identifier: AGPL-3.0-or-later From bab6f01a48474e6b00feb71882be2f4dafe928fc Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 01:21:59 -0300 Subject: [PATCH 5/6] security: avoid global npm package installation --- .github/workflows/npm-build.yml | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/.github/workflows/npm-build.yml b/.github/workflows/npm-build.yml index 8ecf04e..bd92cbc 100644 --- a/.github/workflows/npm-build.yml +++ b/.github/workflows/npm-build.yml @@ -63,15 +63,14 @@ jobs: with: node-version: ${{ steps.versions.outputs.nodeVersion }} - - name: Set up npm - env: - NPM_VERSION: ${{ steps.versions.outputs.npmVersion }} - run: npm install --global "npm@$NPM_VERSION" + - name: Enforce package engine requirements + run: | + npm --version + npm config set engine-strict true - name: Validate package-lock.json run: | - npm install --global npm-package-lock-add-resolved@1.1.4 - npm-package-lock-add-resolved + npm exec --yes --package=npm-package-lock-add-resolved@1.1.4 -- npm-package-lock-add-resolved git --no-pager diff --exit-code - name: Install dependencies and build From ed133eae392733c3bf6272a293e42d5c9fe831f1 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 01:22:15 -0300 Subject: [PATCH 6/6] chore: pin npm build caller to hardened implementation --- workflow-templates/npm-build.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/workflow-templates/npm-build.yml b/workflow-templates/npm-build.yml index d538778..f3029cc 100644 --- a/workflow-templates/npm-build.yml +++ b/workflow-templates/npm-build.yml @@ -13,4 +13,4 @@ permissions: jobs: npm-build: - uses: LibreCodeCoop/github-workflows/.github/workflows/npm-build.yml@3891d93c150cce4b7a21e2456bcf709e3e55ad89 + uses: LibreCodeCoop/github-workflows/.github/workflows/npm-build.yml@bab6f01a48474e6b00feb71882be2f4dafe928fc