Skip to content

Latest commit

 

History

7 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

actions

Shared GitHub Actions for Oxide repos. Each action lives in its own subdirectory and is referenced as oxidecomputer/actions/<name>@<ref>.

setup-node

Installs Node, installs the npm version we require (npm 12 by default), and caches the npm download directory.

Why this exists: our repos require npm ≥12 via devEngines.packageManager in package.json for its supply-chain protections (dependency lifecycle scripts blocked by default and allow-git/allow-remote defaulting to none) and min-release-age support. No shipping Node release bundles npm 12 — Node 22 bundles npm 10, Node 24/26 bundle npm 11 — and actions/setup-node's built-in caching runs npm config get cache with the bundled npm, which fails devEngines validation before a workflow gets a chance to upgrade npm. See actions/setup-node#1553.

This action disables setup-node's caching, installs the required npm globally, then restores/saves the npm cache directory itself, keyed on the runner OS and lockfile hash.

Usage:

steps:
  - uses: actions/checkout@v7
  - uses: oxidecomputer/actions/setup-node@main
    with:
      node-version-file: 'package.json' # default
      npm-version: '12' # default

By default the Node version comes from the consuming repo's package.json (volta.node, devEngines.runtime, or engines.node, in that order), so each repo declares its Node version in one place. Pass node-version to override the file. Note that setup-node installs the newest Node release satisfying the declared range, so an open-ended range like >=24 resolves to the latest major — declare 24 or ^24 to stay on a major line.

Repos using this should also require npm in package.json so the requirement is enforced locally, not just in CI:

"engines": {
  "node": "^24"
},
"devEngines": {
  "packageManager": {
    "name": "npm",
    "version": ">=12",
    "onFail": "error"
  }
}

Because npm 12 blocks dependency lifecycle scripts by default, repos that need them should run npm approve-scripts --allow-scripts-pending, approve the required packages with npm approve-scripts, and commit the resulting allowScripts configuration.

Local dev setup on stock Node (which bundles npm 10 or 11): npm install --global npm@12.

When to delete this action: once the org's Node floor reaches a supported Node LTS release that bundles npm 12 and actions/setup-node#1553 is resolved or moot, consumers can switch back to plain actions/setup-node with cache: npm.

About

Shared GitHub actions

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors