Skip to content

Rebase#506

Merged
jamespepper81 merged 6 commits into
devfrom
main
Jan 27, 2026
Merged

Rebase#506
jamespepper81 merged 6 commits into
devfrom
main

Conversation

@jamespepper81
Copy link
Copy Markdown
Contributor

This pull request updates the GitHub Actions workflows to use the latest version of the actions/checkout action and adds the yaml package as a new dependency. These changes help keep the CI/CD pipeline secure and up-to-date, and introduce support for YAML parsing in the project.

CI/CD Workflow Updates:

  • Updated all references to actions/checkout from version v4 to v6 in the following workflow files to ensure the latest security and performance improvements:
    • .github/workflows/build.yml [1] [2]
    • .github/workflows/dependabot-cocoapods.yml
    • .github/workflows/lint.yml
    • .github/workflows/security.yml [1] [2] [3] [4]

Dependency Management:

  • Added the yaml package (version ^2.8.2) to package.json for YAML file parsing capabilities.

jamespepper81 and others added 6 commits January 27, 2026 08:27
bump lodash from 4.17.21 to 4.17.23
Updates the Android Gradle build system to use Gradle 9.3.0
Fix RNFB script phase outputPaths and update pods
Updates the Node.js setup action used in several GitHub Actions
…lict (#505)

The postcss-load-config@6.0.1 (from tailwindcss) has an optional peer
dependency on yaml@^2.4.2. Without an explicit yaml@2.x in the dependency
tree, npm was incorrectly deduping to yaml@1.10.2, causing CI failures.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@jamespepper81 jamespepper81 merged commit 7f6053b into dev Jan 27, 2026
13 checks passed
jamespepper81 added a commit that referenced this pull request Jan 27, 2026
* fix: add yaml@2.x dependency to resolve postcss-load-config peer conflict (#505)

The postcss-load-config@6.0.1 (from tailwindcss) has an optional peer
dependency on yaml@^2.4.2. Without an explicit yaml@2.x in the dependency
tree, npm was incorrectly deduping to yaml@1.10.2, causing CI failures.



* ci(deps): bump actions/checkout from 4 to 6 (#488)

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...




---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
jamespepper81 added a commit that referenced this pull request Jan 27, 2026
…tions. (#508)

* Rebase (#506)

* fix: add yaml@2.x dependency to resolve postcss-load-config peer conflict (#505)

The postcss-load-config@6.0.1 (from tailwindcss) has an optional peer
dependency on yaml@^2.4.2. Without an explicit yaml@2.x in the dependency
tree, npm was incorrectly deduping to yaml@1.10.2, causing CI failures.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* ci(deps): bump actions/checkout from 4 to 6 (#488)

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* ci(deps): bump actions/cache from 4 to 5 (#487)

Bumps [actions/cache](https://github.com/actions/cache) from 4 to 5.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v5)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: James Pepper <james@bitsleuth.ai>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
jamespepper81 added a commit that referenced this pull request Jan 27, 2026
* Rebase (#506)

* fix: add yaml@2.x dependency to resolve postcss-load-config peer conflict (#505)

The postcss-load-config@6.0.1 (from tailwindcss) has an optional peer
dependency on yaml@^2.4.2. Without an explicit yaml@2.x in the dependency
tree, npm was incorrectly deduping to yaml@1.10.2, causing CI failures.

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>

* ci(deps): bump actions/checkout from 4 to 6 (#488)

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* ci(deps): bump actions/cache from 4 to 5 (#487)

Bumps [actions/cache](https://github.com/actions/cache) from 4 to 5.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v5)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: James Pepper <james@bitsleuth.ai>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant