Repository files navigation

codfish/actions

A collection of reusable GitHub Actions for common development workflows. Each action is self-contained and designed for maximum reusability across different projects.

Table of Contents

Usage

Reference actions using the following format:

uses: codfish/actions/{action-name}@mainuses: codfish/actions/{action-name}@v3uses: codfish/actions/{action-name}@v3.0.1uses: codfish/actions/{action-name}@feature-branchuses: codfish/actions/{action-name}@9f7cf1a3ff9f2838eff5ec9ac69b6ff277610bb2

Available Actions

Creates or updates a comment in a pull request with optional tagging for upsert functionality

Inputs:

InputDescriptionRequiredDefault
messageThe comment message content (supports markdown formatting)Yes-
tagUnique identifier to find and update existing comments (required when upsert is true)No-
upsertUpdate existing comment with matching tag instead of creating new commentNofalse

Usage:

- name: Comment on PRuses: codfish/actions/comment@v3with:
message: '✅ Build successful!'tag: 'build-status'upsert: true

Publishes package with PR-specific version (0.0.0-PR-123--abc1234) using detected package manager (npm/yarn/pnpm) or OIDC trusted publishing, and automatically comments on PR

Inputs:

InputDescriptionRequiredDefault
npm-tokenRegistry authentication token with publish permissions. If not provided, OIDC trusted publishing will be used.No-
tarballPath to pre-built tarball to publish (e.g., '*.tgz'). When provided, publishes the tarball with --ignore-scripts for security. Recommended for pull_request_target workflows to prevent execution of malicious lifecycle scripts.No-
commentWhether to comment on the PR with the published version (true/false)Notrue
comment-tagTag to use for PR comments (for comment identification and updates)Nonpm-publish-pr
devIf true, use dev dependency install syntax in the PR comment (e.g. npm install -D, pnpm add -D).Nofalse

Outputs:

OutputDescription
versionGenerated PR-specific version number (0.0.0-PR-{number}--{short-sha})
package-namePackage name from package.json
error-messageError message if publish fails

Usage:

on: pull_requestjobs:
publish:
permissions:
id-token: writepull-requests: writesteps:
- uses: actions/checkout@v6
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: lts/*
- run: npm run build
- uses: codfish/actions/npm-pr-version@v3

Sets up Node.js environment and installs dependencies with automatic package manager detection (npm/pnpm/yarn), intelligent caching, and version detection via input, .node-version, .nvmrc, or package.json volta.node

Inputs:

InputDescriptionRequiredDefault
node-versionNode.js version to install (e.g. "24", "lts/*"). Precedence: node-version input > .node-version > .nvmrc > package.json volta.node.No-
install-optionsExtra command-line options to pass to npm/pnpm/yarn install.No-
working-directoryDirectory containing package.json and lockfile.No.
registry-urlOptional registry URL to configure for publishing (e.g. "https://registry.npmjs.org/"). Creates .npmrc with NODE_AUTH_TOKEN placeholder. NOT recommended if using semantic-release (it handles auth independently). Only needed for publishing with manual npm publish or other non-semantic-release workflows.No-
upgrade-npmWhether to upgrade npm to v11.5.1. This is required for OIDC trusted publishing but can be disabled if you want to shave off some run time and you are still using token-based authentication.Notrue

Outputs:

OutputDescription
node-versionThe installed node version.
cache-hitWhether the dependency cache was hit (true/false).
pnpm-destExpanded path of pnpm dest.
pnpm-bin-destLocation of pnpm and pnpx command.

Usage:

steps:
- uses: actions/checkout@v6# Will setup node, inferring node version from your codebase & installing your dependencies
- uses: codfish/actions/setup-node-and-install@v3# Or if you want to be explicit
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: 24.4
- run: npm test

Contributing

Each action follows these conventions:

  • Directory structure: Actions are in kebab-case directories at the repository root
  • Required files: action.yml, README.md
  • Composite actions: All actions use composite type for simplicity and transparency
  • Documentation: Each action includes comprehensive usage examples and input/output documentation

Example Workflow

Complete workflow using multiple actions together with secure OIDC trusted publishing:

name: Validateon: pull_request_targetjobs:
# Build and test with untrusted PR code (no secrets)build-and-test:
runs-on: ubuntu-latestpermissions:
contents: readpull-requests: writesteps:
- uses: actions/checkout@v6with:
ref: ${{ github.event.pull_request.head.sha }}
- uses: codfish/actions/setup-node-and-install@v3
- name: Run testsid: testrun: | pnpm test 2>&1 | tee test-output.txt if grep -q "All tests passed" test-output.txt; then echo "status=✅ passed" >> $GITHUB_OUTPUT else echo "status=❌ failed" >> $GITHUB_OUTPUT fi echo "count=$(grep -c "✓\|√\|PASS" test-output.txt || echo "unknown")" >> $GITHUB_OUTPUT - name: Build packageid: buildrun: | pnpm build if [ -d "dist" ]; then size=$(du -sh dist | cut -f1) elif [ -d "build" ]; then size=$(du -sh build | cut -f1) else size="unknown" fi echo "size=$size" >> $GITHUB_OUTPUT - uses: codfish/actions/comment@v3with:
message: | ## 🚀 **Build Summary** **Tests**: ${{ steps.test.outputs.status }} (${{ steps.test.outputs.count }} tests) **Build**: ✅ completed successfully **Size**: ${{ steps.build.outputs.size }} Ready for testing! 🎉tag: 'build-summary'upsert: true
- name: Create package tarballrun: pnpm pack
- uses: actions/upload-artifact@v4with:
name: package-tarballpath: '*.tgz'retention-days: 1# Publish with secrets using only trusted base branch codepublish:
needs: build-and-testruns-on: ubuntu-latestpermissions:
contents: readid-token: writepull-requests: writesteps:
- uses: actions/checkout@v6# No ref = uses base branch (trusted code only)
- uses: codfish/actions/setup-node-and-install@v3
- uses: actions/download-artifact@v4with:
name: package-tarball
- uses: codfish/actions/npm-pr-version@v3with:
tarball: '*.tgz'# Secure: uses --ignore-scriptscomment-tag: 'pr-package'

Maintenance

The release workflow automatically updates the major version tag (v3, v4, v5, etc.) to point to the latest release for that major version. This allows users binding to the major version tag to automatically receive the most recent stable minor/patch releases.

This happens automatically in the release workflow after each successful release.

If you need to update the major version tag manually:

git tag -fa v5 -m "Update v5 tag"&& git push origin v5 --force

Reference: https://github.com/actions/toolkit/blob/main/docs/action-versioning.md#recommendations

Test pull requests in downstream apps before merging

Our validation workflow builds and publishes a multi-arch Docker image to GitHub Container Registry for every pull request, tagging the image with the PR's branch name. You can point downstream repositories at this branch-tagged image to try changes before merging.

- uses: codfish/actions:<branch-name>

About

A collection of GitHub Actions for common workflows. Each action is self-contained and designed for maximum reusability across different projects.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

codfish/actions

A collection of reusable GitHub Actions for common development workflows. Each action is self-contained and designed for maximum reusability across different projects.

Table of Contents

Usage

Reference actions using the following format:

uses: codfish/actions/{action-name}@mainuses: codfish/actions/{action-name}@v3uses: codfish/actions/{action-name}@v3.0.1uses: codfish/actions/{action-name}@feature-branchuses: codfish/actions/{action-name}@9f7cf1a3ff9f2838eff5ec9ac69b6ff277610bb2

Available Actions

Creates or updates a comment in a pull request with optional tagging for upsert functionality

Inputs:

InputDescriptionRequiredDefault
messageThe comment message content (supports markdown formatting)Yes-
tagUnique identifier to find and update existing comments (required when upsert is true)No-
upsertUpdate existing comment with matching tag instead of creating new commentNofalse

Usage:

- name: Comment on PRuses: codfish/actions/comment@v3with:
message: '✅ Build successful!'tag: 'build-status'upsert: true

Publishes package with PR-specific version (0.0.0-PR-123--abc1234) using detected package manager (npm/yarn/pnpm) or OIDC trusted publishing, and automatically comments on PR

Inputs:

InputDescriptionRequiredDefault
npm-tokenRegistry authentication token with publish permissions. If not provided, OIDC trusted publishing will be used.No-
tarballPath to pre-built tarball to publish (e.g., '*.tgz'). When provided, publishes the tarball with --ignore-scripts for security. Recommended for pull_request_target workflows to prevent execution of malicious lifecycle scripts.No-
commentWhether to comment on the PR with the published version (true/false)Notrue
comment-tagTag to use for PR comments (for comment identification and updates)Nonpm-publish-pr
devIf true, use dev dependency install syntax in the PR comment (e.g. npm install -D, pnpm add -D).Nofalse

Outputs:

OutputDescription
versionGenerated PR-specific version number (0.0.0-PR-{number}--{short-sha})
package-namePackage name from package.json
error-messageError message if publish fails

Usage:

on: pull_requestjobs:
publish:
permissions:
id-token: writepull-requests: writesteps:
- uses: actions/checkout@v6
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: lts/*
- run: npm run build
- uses: codfish/actions/npm-pr-version@v3

Sets up Node.js environment and installs dependencies with automatic package manager detection (npm/pnpm/yarn), intelligent caching, and version detection via input, .node-version, .nvmrc, or package.json volta.node

Inputs:

InputDescriptionRequiredDefault
node-versionNode.js version to install (e.g. "24", "lts/*"). Precedence: node-version input > .node-version > .nvmrc > package.json volta.node.No-
install-optionsExtra command-line options to pass to npm/pnpm/yarn install.No-
working-directoryDirectory containing package.json and lockfile.No.
registry-urlOptional registry URL to configure for publishing (e.g. "https://registry.npmjs.org/"). Creates .npmrc with NODE_AUTH_TOKEN placeholder. NOT recommended if using semantic-release (it handles auth independently). Only needed for publishing with manual npm publish or other non-semantic-release workflows.No-
upgrade-npmWhether to upgrade npm to v11.5.1. This is required for OIDC trusted publishing but can be disabled if you want to shave off some run time and you are still using token-based authentication.Notrue

Outputs:

OutputDescription
node-versionThe installed node version.
cache-hitWhether the dependency cache was hit (true/false).
pnpm-destExpanded path of pnpm dest.
pnpm-bin-destLocation of pnpm and pnpx command.

Usage:

steps:
- uses: actions/checkout@v6# Will setup node, inferring node version from your codebase & installing your dependencies
- uses: codfish/actions/setup-node-and-install@v3# Or if you want to be explicit
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: 24.4
- run: npm test

Contributing

Each action follows these conventions:

  • Directory structure: Actions are in kebab-case directories at the repository root
  • Required files: action.yml, README.md
  • Composite actions: All actions use composite type for simplicity and transparency
  • Documentation: Each action includes comprehensive usage examples and input/output documentation

Example Workflow

Complete workflow using multiple actions together with secure OIDC trusted publishing:

name: Validateon: pull_request_targetjobs:
# Build and test with untrusted PR code (no secrets)build-and-test:
runs-on: ubuntu-latestpermissions:
contents: readpull-requests: writesteps:
- uses: actions/checkout@v6with:
ref: ${{ github.event.pull_request.head.sha }}
- uses: codfish/actions/setup-node-and-install@v3
- name: Run testsid: testrun: | pnpm test 2>&1 | tee test-output.txt if grep -q "All tests passed" test-output.txt; then echo "status=✅ passed" >> $GITHUB_OUTPUT else echo "status=❌ failed" >> $GITHUB_OUTPUT fi echo "count=$(grep -c "✓\|√\|PASS" test-output.txt || echo "unknown")" >> $GITHUB_OUTPUT - name: Build packageid: buildrun: | pnpm build if [ -d "dist" ]; then size=$(du -sh dist | cut -f1) elif [ -d "build" ]; then size=$(du -sh build | cut -f1) else size="unknown" fi echo "size=$size" >> $GITHUB_OUTPUT - uses: codfish/actions/comment@v3with:
message: | ## 🚀 **Build Summary** **Tests**: ${{ steps.test.outputs.status }} (${{ steps.test.outputs.count }} tests) **Build**: ✅ completed successfully **Size**: ${{ steps.build.outputs.size }} Ready for testing! 🎉tag: 'build-summary'upsert: true
- name: Create package tarballrun: pnpm pack
- uses: actions/upload-artifact@v4with:
name: package-tarballpath: '*.tgz'retention-days: 1# Publish with secrets using only trusted base branch codepublish:
needs: build-and-testruns-on: ubuntu-latestpermissions:
contents: readid-token: writepull-requests: writesteps:
- uses: actions/checkout@v6# No ref = uses base branch (trusted code only)
- uses: codfish/actions/setup-node-and-install@v3
- uses: actions/download-artifact@v4with:
name: package-tarball
- uses: codfish/actions/npm-pr-version@v3with:
tarball: '*.tgz'# Secure: uses --ignore-scriptscomment-tag: 'pr-package'

Maintenance

The release workflow automatically updates the major version tag (v3, v4, v5, etc.) to point to the latest release for that major version. This allows users binding to the major version tag to automatically receive the most recent stable minor/patch releases.

This happens automatically in the release workflow after each successful release.

If you need to update the major version tag manually:

git tag -fa v5 -m "Update v5 tag"&& git push origin v5 --force

Reference: https://github.com/actions/toolkit/blob/main/docs/action-versioning.md#recommendations

Test pull requests in downstream apps before merging

Our validation workflow builds and publishes a multi-arch Docker image to GitHub Container Registry for every pull request, tagging the image with the PR's branch name. You can point downstream repositories at this branch-tagged image to try changes before merging.

- uses: codfish/actions:<branch-name>

About

A collection of GitHub Actions for common workflows. Each action is self-contained and designed for maximum reusability across different projects.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

codfish/actions

A collection of reusable GitHub Actions for common development workflows. Each action is self-contained and designed for maximum reusability across different projects.

Table of Contents

Usage

Reference actions using the following format:

uses: codfish/actions/{action-name}@mainuses: codfish/actions/{action-name}@v3uses: codfish/actions/{action-name}@v3.0.1uses: codfish/actions/{action-name}@feature-branchuses: codfish/actions/{action-name}@9f7cf1a3ff9f2838eff5ec9ac69b6ff277610bb2

Available Actions

Creates or updates a comment in a pull request with optional tagging for upsert functionality

Inputs:

InputDescriptionRequiredDefault
messageThe comment message content (supports markdown formatting)Yes-
tagUnique identifier to find and update existing comments (required when upsert is true)No-
upsertUpdate existing comment with matching tag instead of creating new commentNofalse

Usage:

- name: Comment on PRuses: codfish/actions/comment@v3with:
message: '✅ Build successful!'tag: 'build-status'upsert: true

Publishes package with PR-specific version (0.0.0-PR-123--abc1234) using detected package manager (npm/yarn/pnpm) or OIDC trusted publishing, and automatically comments on PR

Inputs:

InputDescriptionRequiredDefault
npm-tokenRegistry authentication token with publish permissions. If not provided, OIDC trusted publishing will be used.No-
tarballPath to pre-built tarball to publish (e.g., '*.tgz'). When provided, publishes the tarball with --ignore-scripts for security. Recommended for pull_request_target workflows to prevent execution of malicious lifecycle scripts.No-
commentWhether to comment on the PR with the published version (true/false)Notrue
comment-tagTag to use for PR comments (for comment identification and updates)Nonpm-publish-pr
devIf true, use dev dependency install syntax in the PR comment (e.g. npm install -D, pnpm add -D).Nofalse

Outputs:

OutputDescription
versionGenerated PR-specific version number (0.0.0-PR-{number}--{short-sha})
package-namePackage name from package.json
error-messageError message if publish fails

Usage:

on: pull_requestjobs:
publish:
permissions:
id-token: writepull-requests: writesteps:
- uses: actions/checkout@v6
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: lts/*
- run: npm run build
- uses: codfish/actions/npm-pr-version@v3

Sets up Node.js environment and installs dependencies with automatic package manager detection (npm/pnpm/yarn), intelligent caching, and version detection via input, .node-version, .nvmrc, or package.json volta.node

Inputs:

InputDescriptionRequiredDefault
node-versionNode.js version to install (e.g. "24", "lts/*"). Precedence: node-version input > .node-version > .nvmrc > package.json volta.node.No-
install-optionsExtra command-line options to pass to npm/pnpm/yarn install.No-
working-directoryDirectory containing package.json and lockfile.No.
registry-urlOptional registry URL to configure for publishing (e.g. "https://registry.npmjs.org/"). Creates .npmrc with NODE_AUTH_TOKEN placeholder. NOT recommended if using semantic-release (it handles auth independently). Only needed for publishing with manual npm publish or other non-semantic-release workflows.No-
upgrade-npmWhether to upgrade npm to v11.5.1. This is required for OIDC trusted publishing but can be disabled if you want to shave off some run time and you are still using token-based authentication.Notrue

Outputs:

OutputDescription
node-versionThe installed node version.
cache-hitWhether the dependency cache was hit (true/false).
pnpm-destExpanded path of pnpm dest.
pnpm-bin-destLocation of pnpm and pnpx command.

Usage:

steps:
- uses: actions/checkout@v6# Will setup node, inferring node version from your codebase & installing your dependencies
- uses: codfish/actions/setup-node-and-install@v3# Or if you want to be explicit
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: 24.4
- run: npm test

Contributing

Each action follows these conventions:

  • Directory structure: Actions are in kebab-case directories at the repository root
  • Required files: action.yml, README.md
  • Composite actions: All actions use composite type for simplicity and transparency
  • Documentation: Each action includes comprehensive usage examples and input/output documentation

Example Workflow

Complete workflow using multiple actions together with secure OIDC trusted publishing:

name: Validateon: pull_request_targetjobs:
# Build and test with untrusted PR code (no secrets)build-and-test:
runs-on: ubuntu-latestpermissions:
contents: readpull-requests: writesteps:
- uses: actions/checkout@v6with:
ref: ${{ github.event.pull_request.head.sha }}
- uses: codfish/actions/setup-node-and-install@v3
- name: Run testsid: testrun: | pnpm test 2>&1 | tee test-output.txt if grep -q "All tests passed" test-output.txt; then echo "status=✅ passed" >> $GITHUB_OUTPUT else echo "status=❌ failed" >> $GITHUB_OUTPUT fi echo "count=$(grep -c "✓\|√\|PASS" test-output.txt || echo "unknown")" >> $GITHUB_OUTPUT - name: Build packageid: buildrun: | pnpm build if [ -d "dist" ]; then size=$(du -sh dist | cut -f1) elif [ -d "build" ]; then size=$(du -sh build | cut -f1) else size="unknown" fi echo "size=$size" >> $GITHUB_OUTPUT - uses: codfish/actions/comment@v3with:
message: | ## 🚀 **Build Summary** **Tests**: ${{ steps.test.outputs.status }} (${{ steps.test.outputs.count }} tests) **Build**: ✅ completed successfully **Size**: ${{ steps.build.outputs.size }} Ready for testing! 🎉tag: 'build-summary'upsert: true
- name: Create package tarballrun: pnpm pack
- uses: actions/upload-artifact@v4with:
name: package-tarballpath: '*.tgz'retention-days: 1# Publish with secrets using only trusted base branch codepublish:
needs: build-and-testruns-on: ubuntu-latestpermissions:
contents: readid-token: writepull-requests: writesteps:
- uses: actions/checkout@v6# No ref = uses base branch (trusted code only)
- uses: codfish/actions/setup-node-and-install@v3
- uses: actions/download-artifact@v4with:
name: package-tarball
- uses: codfish/actions/npm-pr-version@v3with:
tarball: '*.tgz'# Secure: uses --ignore-scriptscomment-tag: 'pr-package'

Maintenance

The release workflow automatically updates the major version tag (v3, v4, v5, etc.) to point to the latest release for that major version. This allows users binding to the major version tag to automatically receive the most recent stable minor/patch releases.

This happens automatically in the release workflow after each successful release.

If you need to update the major version tag manually:

git tag -fa v5 -m "Update v5 tag"&& git push origin v5 --force

Reference: https://github.com/actions/toolkit/blob/main/docs/action-versioning.md#recommendations

Test pull requests in downstream apps before merging

Our validation workflow builds and publishes a multi-arch Docker image to GitHub Container Registry for every pull request, tagging the image with the PR's branch name. You can point downstream repositories at this branch-tagged image to try changes before merging.

- uses: codfish/actions:<branch-name>

About

A collection of GitHub Actions for common workflows. Each action is self-contained and designed for maximum reusability across different projects.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

codfish/actions

A collection of reusable GitHub Actions for common development workflows. Each action is self-contained and designed for maximum reusability across different projects.

Table of Contents

Usage

Reference actions using the following format:

uses: codfish/actions/{action-name}@mainuses: codfish/actions/{action-name}@v3uses: codfish/actions/{action-name}@v3.0.1uses: codfish/actions/{action-name}@feature-branchuses: codfish/actions/{action-name}@9f7cf1a3ff9f2838eff5ec9ac69b6ff277610bb2

Available Actions

Creates or updates a comment in a pull request with optional tagging for upsert functionality

Inputs:

InputDescriptionRequiredDefault
messageThe comment message content (supports markdown formatting)Yes-
tagUnique identifier to find and update existing comments (required when upsert is true)No-
upsertUpdate existing comment with matching tag instead of creating new commentNofalse

Usage:

- name: Comment on PRuses: codfish/actions/comment@v3with:
message: '✅ Build successful!'tag: 'build-status'upsert: true

Publishes package with PR-specific version (0.0.0-PR-123--abc1234) using detected package manager (npm/yarn/pnpm) or OIDC trusted publishing, and automatically comments on PR

Inputs:

InputDescriptionRequiredDefault
npm-tokenRegistry authentication token with publish permissions. If not provided, OIDC trusted publishing will be used.No-
tarballPath to pre-built tarball to publish (e.g., '*.tgz'). When provided, publishes the tarball with --ignore-scripts for security. Recommended for pull_request_target workflows to prevent execution of malicious lifecycle scripts.No-
commentWhether to comment on the PR with the published version (true/false)Notrue
comment-tagTag to use for PR comments (for comment identification and updates)Nonpm-publish-pr
devIf true, use dev dependency install syntax in the PR comment (e.g. npm install -D, pnpm add -D).Nofalse

Outputs:

OutputDescription
versionGenerated PR-specific version number (0.0.0-PR-{number}--{short-sha})
package-namePackage name from package.json
error-messageError message if publish fails

Usage:

on: pull_requestjobs:
publish:
permissions:
id-token: writepull-requests: writesteps:
- uses: actions/checkout@v6
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: lts/*
- run: npm run build
- uses: codfish/actions/npm-pr-version@v3

Sets up Node.js environment and installs dependencies with automatic package manager detection (npm/pnpm/yarn), intelligent caching, and version detection via input, .node-version, .nvmrc, or package.json volta.node

Inputs:

InputDescriptionRequiredDefault
node-versionNode.js version to install (e.g. "24", "lts/*"). Precedence: node-version input > .node-version > .nvmrc > package.json volta.node.No-
install-optionsExtra command-line options to pass to npm/pnpm/yarn install.No-
working-directoryDirectory containing package.json and lockfile.No.
registry-urlOptional registry URL to configure for publishing (e.g. "https://registry.npmjs.org/"). Creates .npmrc with NODE_AUTH_TOKEN placeholder. NOT recommended if using semantic-release (it handles auth independently). Only needed for publishing with manual npm publish or other non-semantic-release workflows.No-
upgrade-npmWhether to upgrade npm to v11.5.1. This is required for OIDC trusted publishing but can be disabled if you want to shave off some run time and you are still using token-based authentication.Notrue

Outputs:

OutputDescription
node-versionThe installed node version.
cache-hitWhether the dependency cache was hit (true/false).
pnpm-destExpanded path of pnpm dest.
pnpm-bin-destLocation of pnpm and pnpx command.

Usage:

steps:
- uses: actions/checkout@v6# Will setup node, inferring node version from your codebase & installing your dependencies
- uses: codfish/actions/setup-node-and-install@v3# Or if you want to be explicit
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: 24.4
- run: npm test

Contributing

Each action follows these conventions:

  • Directory structure: Actions are in kebab-case directories at the repository root
  • Required files: action.yml, README.md
  • Composite actions: All actions use composite type for simplicity and transparency
  • Documentation: Each action includes comprehensive usage examples and input/output documentation

Example Workflow

Complete workflow using multiple actions together with secure OIDC trusted publishing:

name: Validateon: pull_request_targetjobs:
# Build and test with untrusted PR code (no secrets)build-and-test:
runs-on: ubuntu-latestpermissions:
contents: readpull-requests: writesteps:
- uses: actions/checkout@v6with:
ref: ${{ github.event.pull_request.head.sha }}
- uses: codfish/actions/setup-node-and-install@v3
- name: Run testsid: testrun: | pnpm test 2>&1 | tee test-output.txt if grep -q "All tests passed" test-output.txt; then echo "status=✅ passed" >> $GITHUB_OUTPUT else echo "status=❌ failed" >> $GITHUB_OUTPUT fi echo "count=$(grep -c "✓\|√\|PASS" test-output.txt || echo "unknown")" >> $GITHUB_OUTPUT - name: Build packageid: buildrun: | pnpm build if [ -d "dist" ]; then size=$(du -sh dist | cut -f1) elif [ -d "build" ]; then size=$(du -sh build | cut -f1) else size="unknown" fi echo "size=$size" >> $GITHUB_OUTPUT - uses: codfish/actions/comment@v3with:
message: | ## 🚀 **Build Summary** **Tests**: ${{ steps.test.outputs.status }} (${{ steps.test.outputs.count }} tests) **Build**: ✅ completed successfully **Size**: ${{ steps.build.outputs.size }} Ready for testing! 🎉tag: 'build-summary'upsert: true
- name: Create package tarballrun: pnpm pack
- uses: actions/upload-artifact@v4with:
name: package-tarballpath: '*.tgz'retention-days: 1# Publish with secrets using only trusted base branch codepublish:
needs: build-and-testruns-on: ubuntu-latestpermissions:
contents: readid-token: writepull-requests: writesteps:
- uses: actions/checkout@v6# No ref = uses base branch (trusted code only)
- uses: codfish/actions/setup-node-and-install@v3
- uses: actions/download-artifact@v4with:
name: package-tarball
- uses: codfish/actions/npm-pr-version@v3with:
tarball: '*.tgz'# Secure: uses --ignore-scriptscomment-tag: 'pr-package'

Maintenance

The release workflow automatically updates the major version tag (v3, v4, v5, etc.) to point to the latest release for that major version. This allows users binding to the major version tag to automatically receive the most recent stable minor/patch releases.

This happens automatically in the release workflow after each successful release.

If you need to update the major version tag manually:

git tag -fa v5 -m "Update v5 tag"&& git push origin v5 --force

Reference: https://github.com/actions/toolkit/blob/main/docs/action-versioning.md#recommendations

Test pull requests in downstream apps before merging

Our validation workflow builds and publishes a multi-arch Docker image to GitHub Container Registry for every pull request, tagging the image with the PR's branch name. You can point downstream repositories at this branch-tagged image to try changes before merging.

- uses: codfish/actions:<branch-name>

About

A collection of GitHub Actions for common workflows. Each action is self-contained and designed for maximum reusability across different projects.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

codfish/actions

A collection of reusable GitHub Actions for common development workflows. Each action is self-contained and designed for maximum reusability across different projects.

Table of Contents

Usage

Reference actions using the following format:

uses: codfish/actions/{action-name}@mainuses: codfish/actions/{action-name}@v3uses: codfish/actions/{action-name}@v3.0.1uses: codfish/actions/{action-name}@feature-branchuses: codfish/actions/{action-name}@9f7cf1a3ff9f2838eff5ec9ac69b6ff277610bb2

Available Actions

Creates or updates a comment in a pull request with optional tagging for upsert functionality

Inputs:

InputDescriptionRequiredDefault
messageThe comment message content (supports markdown formatting)Yes-
tagUnique identifier to find and update existing comments (required when upsert is true)No-
upsertUpdate existing comment with matching tag instead of creating new commentNofalse

Usage:

- name: Comment on PRuses: codfish/actions/comment@v3with:
message: '✅ Build successful!'tag: 'build-status'upsert: true

Publishes package with PR-specific version (0.0.0-PR-123--abc1234) using detected package manager (npm/yarn/pnpm) or OIDC trusted publishing, and automatically comments on PR

Inputs:

InputDescriptionRequiredDefault
npm-tokenRegistry authentication token with publish permissions. If not provided, OIDC trusted publishing will be used.No-
tarballPath to pre-built tarball to publish (e.g., '*.tgz'). When provided, publishes the tarball with --ignore-scripts for security. Recommended for pull_request_target workflows to prevent execution of malicious lifecycle scripts.No-
commentWhether to comment on the PR with the published version (true/false)Notrue
comment-tagTag to use for PR comments (for comment identification and updates)Nonpm-publish-pr
devIf true, use dev dependency install syntax in the PR comment (e.g. npm install -D, pnpm add -D).Nofalse

Outputs:

OutputDescription
versionGenerated PR-specific version number (0.0.0-PR-{number}--{short-sha})
package-namePackage name from package.json
error-messageError message if publish fails

Usage:

on: pull_requestjobs:
publish:
permissions:
id-token: writepull-requests: writesteps:
- uses: actions/checkout@v6
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: lts/*
- run: npm run build
- uses: codfish/actions/npm-pr-version@v3

Sets up Node.js environment and installs dependencies with automatic package manager detection (npm/pnpm/yarn), intelligent caching, and version detection via input, .node-version, .nvmrc, or package.json volta.node

Inputs:

InputDescriptionRequiredDefault
node-versionNode.js version to install (e.g. "24", "lts/*"). Precedence: node-version input > .node-version > .nvmrc > package.json volta.node.No-
install-optionsExtra command-line options to pass to npm/pnpm/yarn install.No-
working-directoryDirectory containing package.json and lockfile.No.
registry-urlOptional registry URL to configure for publishing (e.g. "https://registry.npmjs.org/"). Creates .npmrc with NODE_AUTH_TOKEN placeholder. NOT recommended if using semantic-release (it handles auth independently). Only needed for publishing with manual npm publish or other non-semantic-release workflows.No-
upgrade-npmWhether to upgrade npm to v11.5.1. This is required for OIDC trusted publishing but can be disabled if you want to shave off some run time and you are still using token-based authentication.Notrue

Outputs:

OutputDescription
node-versionThe installed node version.
cache-hitWhether the dependency cache was hit (true/false).
pnpm-destExpanded path of pnpm dest.
pnpm-bin-destLocation of pnpm and pnpx command.

Usage:

steps:
- uses: actions/checkout@v6# Will setup node, inferring node version from your codebase & installing your dependencies
- uses: codfish/actions/setup-node-and-install@v3# Or if you want to be explicit
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: 24.4
- run: npm test

Contributing

Each action follows these conventions:

  • Directory structure: Actions are in kebab-case directories at the repository root
  • Required files: action.yml, README.md
  • Composite actions: All actions use composite type for simplicity and transparency
  • Documentation: Each action includes comprehensive usage examples and input/output documentation

Example Workflow

Complete workflow using multiple actions together with secure OIDC trusted publishing:

name: Validateon: pull_request_targetjobs:
# Build and test with untrusted PR code (no secrets)build-and-test:
runs-on: ubuntu-latestpermissions:
contents: readpull-requests: writesteps:
- uses: actions/checkout@v6with:
ref: ${{ github.event.pull_request.head.sha }}
- uses: codfish/actions/setup-node-and-install@v3
- name: Run testsid: testrun: | pnpm test 2>&1 | tee test-output.txt if grep -q "All tests passed" test-output.txt; then echo "status=✅ passed" >> $GITHUB_OUTPUT else echo "status=❌ failed" >> $GITHUB_OUTPUT fi echo "count=$(grep -c "✓\|√\|PASS" test-output.txt || echo "unknown")" >> $GITHUB_OUTPUT - name: Build packageid: buildrun: | pnpm build if [ -d "dist" ]; then size=$(du -sh dist | cut -f1) elif [ -d "build" ]; then size=$(du -sh build | cut -f1) else size="unknown" fi echo "size=$size" >> $GITHUB_OUTPUT - uses: codfish/actions/comment@v3with:
message: | ## 🚀 **Build Summary** **Tests**: ${{ steps.test.outputs.status }} (${{ steps.test.outputs.count }} tests) **Build**: ✅ completed successfully **Size**: ${{ steps.build.outputs.size }} Ready for testing! 🎉tag: 'build-summary'upsert: true
- name: Create package tarballrun: pnpm pack
- uses: actions/upload-artifact@v4with:
name: package-tarballpath: '*.tgz'retention-days: 1# Publish with secrets using only trusted base branch codepublish:
needs: build-and-testruns-on: ubuntu-latestpermissions:
contents: readid-token: writepull-requests: writesteps:
- uses: actions/checkout@v6# No ref = uses base branch (trusted code only)
- uses: codfish/actions/setup-node-and-install@v3
- uses: actions/download-artifact@v4with:
name: package-tarball
- uses: codfish/actions/npm-pr-version@v3with:
tarball: '*.tgz'# Secure: uses --ignore-scriptscomment-tag: 'pr-package'

Maintenance

The release workflow automatically updates the major version tag (v3, v4, v5, etc.) to point to the latest release for that major version. This allows users binding to the major version tag to automatically receive the most recent stable minor/patch releases.

This happens automatically in the release workflow after each successful release.

If you need to update the major version tag manually:

git tag -fa v5 -m "Update v5 tag"&& git push origin v5 --force

Reference: https://github.com/actions/toolkit/blob/main/docs/action-versioning.md#recommendations

Test pull requests in downstream apps before merging

Our validation workflow builds and publishes a multi-arch Docker image to GitHub Container Registry for every pull request, tagging the image with the PR's branch name. You can point downstream repositories at this branch-tagged image to try changes before merging.

- uses: codfish/actions:<branch-name>

About

A collection of GitHub Actions for common workflows. Each action is self-contained and designed for maximum reusability across different projects.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

codfish/actions

A collection of reusable GitHub Actions for common development workflows. Each action is self-contained and designed for maximum reusability across different projects.

Table of Contents

Usage

Reference actions using the following format:

uses: codfish/actions/{action-name}@mainuses: codfish/actions/{action-name}@v3uses: codfish/actions/{action-name}@v3.0.1uses: codfish/actions/{action-name}@feature-branchuses: codfish/actions/{action-name}@9f7cf1a3ff9f2838eff5ec9ac69b6ff277610bb2

Available Actions

Creates or updates a comment in a pull request with optional tagging for upsert functionality

Inputs:

InputDescriptionRequiredDefault
messageThe comment message content (supports markdown formatting)Yes-
tagUnique identifier to find and update existing comments (required when upsert is true)No-
upsertUpdate existing comment with matching tag instead of creating new commentNofalse

Usage:

- name: Comment on PRuses: codfish/actions/comment@v3with:
message: '✅ Build successful!'tag: 'build-status'upsert: true

Publishes package with PR-specific version (0.0.0-PR-123--abc1234) using detected package manager (npm/yarn/pnpm) or OIDC trusted publishing, and automatically comments on PR

Inputs:

InputDescriptionRequiredDefault
npm-tokenRegistry authentication token with publish permissions. If not provided, OIDC trusted publishing will be used.No-
tarballPath to pre-built tarball to publish (e.g., '*.tgz'). When provided, publishes the tarball with --ignore-scripts for security. Recommended for pull_request_target workflows to prevent execution of malicious lifecycle scripts.No-
commentWhether to comment on the PR with the published version (true/false)Notrue
comment-tagTag to use for PR comments (for comment identification and updates)Nonpm-publish-pr
devIf true, use dev dependency install syntax in the PR comment (e.g. npm install -D, pnpm add -D).Nofalse

Outputs:

OutputDescription
versionGenerated PR-specific version number (0.0.0-PR-{number}--{short-sha})
package-namePackage name from package.json
error-messageError message if publish fails

Usage:

on: pull_requestjobs:
publish:
permissions:
id-token: writepull-requests: writesteps:
- uses: actions/checkout@v6
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: lts/*
- run: npm run build
- uses: codfish/actions/npm-pr-version@v3

Sets up Node.js environment and installs dependencies with automatic package manager detection (npm/pnpm/yarn), intelligent caching, and version detection via input, .node-version, .nvmrc, or package.json volta.node

Inputs:

InputDescriptionRequiredDefault
node-versionNode.js version to install (e.g. "24", "lts/*"). Precedence: node-version input > .node-version > .nvmrc > package.json volta.node.No-
install-optionsExtra command-line options to pass to npm/pnpm/yarn install.No-
working-directoryDirectory containing package.json and lockfile.No.
registry-urlOptional registry URL to configure for publishing (e.g. "https://registry.npmjs.org/"). Creates .npmrc with NODE_AUTH_TOKEN placeholder. NOT recommended if using semantic-release (it handles auth independently). Only needed for publishing with manual npm publish or other non-semantic-release workflows.No-
upgrade-npmWhether to upgrade npm to v11.5.1. This is required for OIDC trusted publishing but can be disabled if you want to shave off some run time and you are still using token-based authentication.Notrue

Outputs:

OutputDescription
node-versionThe installed node version.
cache-hitWhether the dependency cache was hit (true/false).
pnpm-destExpanded path of pnpm dest.
pnpm-bin-destLocation of pnpm and pnpx command.

Usage:

steps:
- uses: actions/checkout@v6# Will setup node, inferring node version from your codebase & installing your dependencies
- uses: codfish/actions/setup-node-and-install@v3# Or if you want to be explicit
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: 24.4
- run: npm test

Contributing

Each action follows these conventions:

  • Directory structure: Actions are in kebab-case directories at the repository root
  • Required files: action.yml, README.md
  • Composite actions: All actions use composite type for simplicity and transparency
  • Documentation: Each action includes comprehensive usage examples and input/output documentation

Example Workflow

Complete workflow using multiple actions together with secure OIDC trusted publishing:

name: Validateon: pull_request_targetjobs:
# Build and test with untrusted PR code (no secrets)build-and-test:
runs-on: ubuntu-latestpermissions:
contents: readpull-requests: writesteps:
- uses: actions/checkout@v6with:
ref: ${{ github.event.pull_request.head.sha }}
- uses: codfish/actions/setup-node-and-install@v3
- name: Run testsid: testrun: | pnpm test 2>&1 | tee test-output.txt if grep -q "All tests passed" test-output.txt; then echo "status=✅ passed" >> $GITHUB_OUTPUT else echo "status=❌ failed" >> $GITHUB_OUTPUT fi echo "count=$(grep -c "✓\|√\|PASS" test-output.txt || echo "unknown")" >> $GITHUB_OUTPUT - name: Build packageid: buildrun: | pnpm build if [ -d "dist" ]; then size=$(du -sh dist | cut -f1) elif [ -d "build" ]; then size=$(du -sh build | cut -f1) else size="unknown" fi echo "size=$size" >> $GITHUB_OUTPUT - uses: codfish/actions/comment@v3with:
message: | ## 🚀 **Build Summary** **Tests**: ${{ steps.test.outputs.status }} (${{ steps.test.outputs.count }} tests) **Build**: ✅ completed successfully **Size**: ${{ steps.build.outputs.size }} Ready for testing! 🎉tag: 'build-summary'upsert: true
- name: Create package tarballrun: pnpm pack
- uses: actions/upload-artifact@v4with:
name: package-tarballpath: '*.tgz'retention-days: 1# Publish with secrets using only trusted base branch codepublish:
needs: build-and-testruns-on: ubuntu-latestpermissions:
contents: readid-token: writepull-requests: writesteps:
- uses: actions/checkout@v6# No ref = uses base branch (trusted code only)
- uses: codfish/actions/setup-node-and-install@v3
- uses: actions/download-artifact@v4with:
name: package-tarball
- uses: codfish/actions/npm-pr-version@v3with:
tarball: '*.tgz'# Secure: uses --ignore-scriptscomment-tag: 'pr-package'

Maintenance

The release workflow automatically updates the major version tag (v3, v4, v5, etc.) to point to the latest release for that major version. This allows users binding to the major version tag to automatically receive the most recent stable minor/patch releases.

This happens automatically in the release workflow after each successful release.

If you need to update the major version tag manually:

git tag -fa v5 -m "Update v5 tag"&& git push origin v5 --force

Reference: https://github.com/actions/toolkit/blob/main/docs/action-versioning.md#recommendations

Test pull requests in downstream apps before merging

Our validation workflow builds and publishes a multi-arch Docker image to GitHub Container Registry for every pull request, tagging the image with the PR's branch name. You can point downstream repositories at this branch-tagged image to try changes before merging.

- uses: codfish/actions:<branch-name>

About

A collection of GitHub Actions for common workflows. Each action is self-contained and designed for maximum reusability across different projects.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

codfish/actions

A collection of reusable GitHub Actions for common development workflows. Each action is self-contained and designed for maximum reusability across different projects.

Table of Contents

Usage

Reference actions using the following format:

uses: codfish/actions/{action-name}@mainuses: codfish/actions/{action-name}@v3uses: codfish/actions/{action-name}@v3.0.1uses: codfish/actions/{action-name}@feature-branchuses: codfish/actions/{action-name}@9f7cf1a3ff9f2838eff5ec9ac69b6ff277610bb2

Available Actions

Creates or updates a comment in a pull request with optional tagging for upsert functionality

Inputs:

InputDescriptionRequiredDefault
messageThe comment message content (supports markdown formatting)Yes-
tagUnique identifier to find and update existing comments (required when upsert is true)No-
upsertUpdate existing comment with matching tag instead of creating new commentNofalse

Usage:

- name: Comment on PRuses: codfish/actions/comment@v3with:
message: '✅ Build successful!'tag: 'build-status'upsert: true

Publishes package with PR-specific version (0.0.0-PR-123--abc1234) using detected package manager (npm/yarn/pnpm) or OIDC trusted publishing, and automatically comments on PR

Inputs:

InputDescriptionRequiredDefault
npm-tokenRegistry authentication token with publish permissions. If not provided, OIDC trusted publishing will be used.No-
tarballPath to pre-built tarball to publish (e.g., '*.tgz'). When provided, publishes the tarball with --ignore-scripts for security. Recommended for pull_request_target workflows to prevent execution of malicious lifecycle scripts.No-
commentWhether to comment on the PR with the published version (true/false)Notrue
comment-tagTag to use for PR comments (for comment identification and updates)Nonpm-publish-pr
devIf true, use dev dependency install syntax in the PR comment (e.g. npm install -D, pnpm add -D).Nofalse

Outputs:

OutputDescription
versionGenerated PR-specific version number (0.0.0-PR-{number}--{short-sha})
package-namePackage name from package.json
error-messageError message if publish fails

Usage:

on: pull_requestjobs:
publish:
permissions:
id-token: writepull-requests: writesteps:
- uses: actions/checkout@v6
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: lts/*
- run: npm run build
- uses: codfish/actions/npm-pr-version@v3

Sets up Node.js environment and installs dependencies with automatic package manager detection (npm/pnpm/yarn), intelligent caching, and version detection via input, .node-version, .nvmrc, or package.json volta.node

Inputs:

InputDescriptionRequiredDefault
node-versionNode.js version to install (e.g. "24", "lts/*"). Precedence: node-version input > .node-version > .nvmrc > package.json volta.node.No-
install-optionsExtra command-line options to pass to npm/pnpm/yarn install.No-
working-directoryDirectory containing package.json and lockfile.No.
registry-urlOptional registry URL to configure for publishing (e.g. "https://registry.npmjs.org/"). Creates .npmrc with NODE_AUTH_TOKEN placeholder. NOT recommended if using semantic-release (it handles auth independently). Only needed for publishing with manual npm publish or other non-semantic-release workflows.No-
upgrade-npmWhether to upgrade npm to v11.5.1. This is required for OIDC trusted publishing but can be disabled if you want to shave off some run time and you are still using token-based authentication.Notrue

Outputs:

OutputDescription
node-versionThe installed node version.
cache-hitWhether the dependency cache was hit (true/false).
pnpm-destExpanded path of pnpm dest.
pnpm-bin-destLocation of pnpm and pnpx command.

Usage:

steps:
- uses: actions/checkout@v6# Will setup node, inferring node version from your codebase & installing your dependencies
- uses: codfish/actions/setup-node-and-install@v3# Or if you want to be explicit
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: 24.4
- run: npm test

Contributing

Each action follows these conventions:

  • Directory structure: Actions are in kebab-case directories at the repository root
  • Required files: action.yml, README.md
  • Composite actions: All actions use composite type for simplicity and transparency
  • Documentation: Each action includes comprehensive usage examples and input/output documentation

Example Workflow

Complete workflow using multiple actions together with secure OIDC trusted publishing:

name: Validateon: pull_request_targetjobs:
# Build and test with untrusted PR code (no secrets)build-and-test:
runs-on: ubuntu-latestpermissions:
contents: readpull-requests: writesteps:
- uses: actions/checkout@v6with:
ref: ${{ github.event.pull_request.head.sha }}
- uses: codfish/actions/setup-node-and-install@v3
- name: Run testsid: testrun: | pnpm test 2>&1 | tee test-output.txt if grep -q "All tests passed" test-output.txt; then echo "status=✅ passed" >> $GITHUB_OUTPUT else echo "status=❌ failed" >> $GITHUB_OUTPUT fi echo "count=$(grep -c "✓\|√\|PASS" test-output.txt || echo "unknown")" >> $GITHUB_OUTPUT - name: Build packageid: buildrun: | pnpm build if [ -d "dist" ]; then size=$(du -sh dist | cut -f1) elif [ -d "build" ]; then size=$(du -sh build | cut -f1) else size="unknown" fi echo "size=$size" >> $GITHUB_OUTPUT - uses: codfish/actions/comment@v3with:
message: | ## 🚀 **Build Summary** **Tests**: ${{ steps.test.outputs.status }} (${{ steps.test.outputs.count }} tests) **Build**: ✅ completed successfully **Size**: ${{ steps.build.outputs.size }} Ready for testing! 🎉tag: 'build-summary'upsert: true
- name: Create package tarballrun: pnpm pack
- uses: actions/upload-artifact@v4with:
name: package-tarballpath: '*.tgz'retention-days: 1# Publish with secrets using only trusted base branch codepublish:
needs: build-and-testruns-on: ubuntu-latestpermissions:
contents: readid-token: writepull-requests: writesteps:
- uses: actions/checkout@v6# No ref = uses base branch (trusted code only)
- uses: codfish/actions/setup-node-and-install@v3
- uses: actions/download-artifact@v4with:
name: package-tarball
- uses: codfish/actions/npm-pr-version@v3with:
tarball: '*.tgz'# Secure: uses --ignore-scriptscomment-tag: 'pr-package'

Maintenance

The release workflow automatically updates the major version tag (v3, v4, v5, etc.) to point to the latest release for that major version. This allows users binding to the major version tag to automatically receive the most recent stable minor/patch releases.

This happens automatically in the release workflow after each successful release.

If you need to update the major version tag manually:

git tag -fa v5 -m "Update v5 tag"&& git push origin v5 --force

Reference: https://github.com/actions/toolkit/blob/main/docs/action-versioning.md#recommendations

Test pull requests in downstream apps before merging

Our validation workflow builds and publishes a multi-arch Docker image to GitHub Container Registry for every pull request, tagging the image with the PR's branch name. You can point downstream repositories at this branch-tagged image to try changes before merging.

- uses: codfish/actions:<branch-name>

About

A collection of GitHub Actions for common workflows. Each action is self-contained and designed for maximum reusability across different projects.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

codfish/actions

A collection of reusable GitHub Actions for common development workflows. Each action is self-contained and designed for maximum reusability across different projects.

Table of Contents

Usage

Reference actions using the following format:

uses: codfish/actions/{action-name}@mainuses: codfish/actions/{action-name}@v3uses: codfish/actions/{action-name}@v3.0.1uses: codfish/actions/{action-name}@feature-branchuses: codfish/actions/{action-name}@9f7cf1a3ff9f2838eff5ec9ac69b6ff277610bb2

Available Actions

Creates or updates a comment in a pull request with optional tagging for upsert functionality

Inputs:

InputDescriptionRequiredDefault
messageThe comment message content (supports markdown formatting)Yes-
tagUnique identifier to find and update existing comments (required when upsert is true)No-
upsertUpdate existing comment with matching tag instead of creating new commentNofalse

Usage:

- name: Comment on PRuses: codfish/actions/comment@v3with:
message: '✅ Build successful!'tag: 'build-status'upsert: true

Publishes package with PR-specific version (0.0.0-PR-123--abc1234) using detected package manager (npm/yarn/pnpm) or OIDC trusted publishing, and automatically comments on PR

Inputs:

InputDescriptionRequiredDefault
npm-tokenRegistry authentication token with publish permissions. If not provided, OIDC trusted publishing will be used.No-
tarballPath to pre-built tarball to publish (e.g., '*.tgz'). When provided, publishes the tarball with --ignore-scripts for security. Recommended for pull_request_target workflows to prevent execution of malicious lifecycle scripts.No-
commentWhether to comment on the PR with the published version (true/false)Notrue
comment-tagTag to use for PR comments (for comment identification and updates)Nonpm-publish-pr
devIf true, use dev dependency install syntax in the PR comment (e.g. npm install -D, pnpm add -D).Nofalse

Outputs:

OutputDescription
versionGenerated PR-specific version number (0.0.0-PR-{number}--{short-sha})
package-namePackage name from package.json
error-messageError message if publish fails

Usage:

on: pull_requestjobs:
publish:
permissions:
id-token: writepull-requests: writesteps:
- uses: actions/checkout@v6
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: lts/*
- run: npm run build
- uses: codfish/actions/npm-pr-version@v3

Sets up Node.js environment and installs dependencies with automatic package manager detection (npm/pnpm/yarn), intelligent caching, and version detection via input, .node-version, .nvmrc, or package.json volta.node

Inputs:

InputDescriptionRequiredDefault
node-versionNode.js version to install (e.g. "24", "lts/*"). Precedence: node-version input > .node-version > .nvmrc > package.json volta.node.No-
install-optionsExtra command-line options to pass to npm/pnpm/yarn install.No-
working-directoryDirectory containing package.json and lockfile.No.
registry-urlOptional registry URL to configure for publishing (e.g. "https://registry.npmjs.org/"). Creates .npmrc with NODE_AUTH_TOKEN placeholder. NOT recommended if using semantic-release (it handles auth independently). Only needed for publishing with manual npm publish or other non-semantic-release workflows.No-
upgrade-npmWhether to upgrade npm to v11.5.1. This is required for OIDC trusted publishing but can be disabled if you want to shave off some run time and you are still using token-based authentication.Notrue

Outputs:

OutputDescription
node-versionThe installed node version.
cache-hitWhether the dependency cache was hit (true/false).
pnpm-destExpanded path of pnpm dest.
pnpm-bin-destLocation of pnpm and pnpx command.

Usage:

steps:
- uses: actions/checkout@v6# Will setup node, inferring node version from your codebase & installing your dependencies
- uses: codfish/actions/setup-node-and-install@v3# Or if you want to be explicit
- uses: codfish/actions/setup-node-and-install@v3with:
node-version: 24.4
- run: npm test

Contributing

Each action follows these conventions:

  • Directory structure: Actions are in kebab-case directories at the repository root
  • Required files: action.yml, README.md
  • Composite actions: All actions use composite type for simplicity and transparency
  • Documentation: Each action includes comprehensive usage examples and input/output documentation

Example Workflow

Complete workflow using multiple actions together with secure OIDC trusted publishing:

name: Validateon: pull_request_targetjobs:
# Build and test with untrusted PR code (no secrets)build-and-test:
runs-on: ubuntu-latestpermissions:
contents: readpull-requests: writesteps:
- uses: actions/checkout@v6with:
ref: ${{ github.event.pull_request.head.sha }}
- uses: codfish/actions/setup-node-and-install@v3
- name: Run testsid: testrun: | pnpm test 2>&1 | tee test-output.txt if grep -q "All tests passed" test-output.txt; then echo "status=✅ passed" >> $GITHUB_OUTPUT else echo "status=❌ failed" >> $GITHUB_OUTPUT fi echo "count=$(grep -c "✓\|√\|PASS" test-output.txt || echo "unknown")" >> $GITHUB_OUTPUT - name: Build packageid: buildrun: | pnpm build if [ -d "dist" ]; then size=$(du -sh dist | cut -f1) elif [ -d "build" ]; then size=$(du -sh build | cut -f1) else size="unknown" fi echo "size=$size" >> $GITHUB_OUTPUT - uses: codfish/actions/comment@v3with:
message: | ## 🚀 **Build Summary** **Tests**: ${{ steps.test.outputs.status }} (${{ steps.test.outputs.count }} tests) **Build**: ✅ completed successfully **Size**: ${{ steps.build.outputs.size }} Ready for testing! 🎉tag: 'build-summary'upsert: true
- name: Create package tarballrun: pnpm pack
- uses: actions/upload-artifact@v4with:
name: package-tarballpath: '*.tgz'retention-days: 1# Publish with secrets using only trusted base branch codepublish:
needs: build-and-testruns-on: ubuntu-latestpermissions:
contents: readid-token: writepull-requests: writesteps:
- uses: actions/checkout@v6# No ref = uses base branch (trusted code only)
- uses: codfish/actions/setup-node-and-install@v3
- uses: actions/download-artifact@v4with:
name: package-tarball
- uses: codfish/actions/npm-pr-version@v3with:
tarball: '*.tgz'# Secure: uses --ignore-scriptscomment-tag: 'pr-package'

Maintenance

The release workflow automatically updates the major version tag (v3, v4, v5, etc.) to point to the latest release for that major version. This allows users binding to the major version tag to automatically receive the most recent stable minor/patch releases.

This happens automatically in the release workflow after each successful release.

If you need to update the major version tag manually:

git tag -fa v5 -m "Update v5 tag"&& git push origin v5 --force

Reference: https://github.com/actions/toolkit/blob/main/docs/action-versioning.md#recommendations

Test pull requests in downstream apps before merging

Our validation workflow builds and publishes a multi-arch Docker image to GitHub Container Registry for every pull request, tagging the image with the PR's branch name. You can point downstream repositories at this branch-tagged image to try changes before merging.

- uses: codfish/actions:<branch-name>

About

A collection of GitHub Actions for common workflows. Each action is self-contained and designed for maximum reusability across different projects.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages