Reorganized CI/CD quality gate workflows to independently verify desktop and mobile app changes for streamlined continuous integration processes.
<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit
* **Chores**
* Reorganized CI/CD quality gate workflows to independently verify desktop and mobile app changes for streamlined continuous integration processes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
The PR separates the PR quality gate workflows by platform: the desktop workflow is narrowed to desktop-only changes, and a new mobile-specific workflow is created to enforce the same lint and format checks for mobile code independently.
Changes
Platform-specific CI workflows
Layer / File(s)
Summary
Separate desktop and mobile quality gate workflows .github/workflows/pr-quality-gate-desktop.yml, .github/workflows/pr-quality-gate-mobile.yml
Desktop workflow refactored to trigger only on js/desktop/** changes with a single verify job; new mobile workflow created to independently enforce yarn lint and yarn format:check on js/mobile/** changes, both using Node.js 20 with immutable dependency installation.
Estimated code review effort
🎯 2 (Simple) | ⏱️ ~8 minutes
Poem
🐰 Workflows split clean, like a path through the wood,
Desktop and mobile, each does its own good,
Quality gates stand guard on their respective ways,
Lint and format checks through all of our days! ✨
Check skipped - CodeRabbit’s high-level summary is enabled.
Title check
✅ Passed
The title 'ci: split pr quality gates for mobile and desktop' accurately and concisely describes the main change in the changeset.
Docstring Coverage
✅ Passed
No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check
✅ Passed
Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check
✅ Passed
Check skipped because no linked issues were found for this pull request.
✏️ Tip: You can configure your own custom pre-merge checks in the settings.
✨ Finishing Touches🧪 Generate unit tests (beta)
Create PR with unit tests
Commit unit tests in branch fix-pr-quality-gates
Comment @coderabbitai help to get the list of available commands and usage tips.
<!-- This is an auto-generated comment: summarize by coderabbit.ai -->
<!-- review_stack_entry_start -->
[](https://app.coderabbit.ai/change-stack/flowy-live/llink/pull/268?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)
<!-- review_stack_entry_end -->
<!-- walkthrough_start -->
<details>
<summary>📝 Walkthrough</summary>
## Walkthrough
The PR separates the PR quality gate workflows by platform: the desktop workflow is narrowed to desktop-only changes, and a new mobile-specific workflow is created to enforce the same lint and format checks for mobile code independently.
## Changes
**Platform-specific CI workflows**
|Layer / File(s)|Summary|
|---|---|
|**Separate desktop and mobile quality gate workflows** <br> `.github/workflows/pr-quality-gate-desktop.yml`, `.github/workflows/pr-quality-gate-mobile.yml`|Desktop workflow refactored to trigger only on `js/desktop/**` changes with a single `verify` job; new mobile workflow created to independently enforce `yarn lint` and `yarn format:check` on `js/mobile/**` changes, both using Node.js 20 with immutable dependency installation.|
## Estimated code review effort
🎯 2 (Simple) | ⏱️ ~8 minutes
## Poem
> 🐰 Workflows split clean, like a path through the wood,
> Desktop and mobile, each does its own good,
> Quality gates stand guard on their respective ways,
> Lint and format checks through all of our days! ✨
</details>
<!-- walkthrough_end -->
<!-- pre_merge_checks_walkthrough_start -->
<details>
<summary>🚥 Pre-merge checks | ✅ 5</summary>
<details>
<summary>✅ Passed checks (5 passed)</summary>
| Check name | Status | Explanation |
| :------------------------: | :------- | :--------------------------------------------------------------------------------------------------------------------------------- |
| Description Check | ✅ Passed | Check skipped - CodeRabbit’s high-level summary is enabled. |
| Title check | ✅ Passed | The title 'ci: split pr quality gates for mobile and desktop' accurately and concisely describes the main change in the changeset. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
</details>
<sub>✏️ Tip: You can configure your own custom pre-merge checks in the settings.</sub>
</details>
<!-- pre_merge_checks_walkthrough_end -->
<!-- finishing_touch_checkbox_start -->
<details>
<summary>✨ Finishing Touches</summary>
<details>
<summary>🧪 Generate unit tests (beta)</summary>
- [ ] <!-- {"checkboxId": "f47ac10b-58cc-4372-a567-0e02b2c3d479", "radioGroupId": "utg-output-choice-group-unknown_comment_id"} --> Create PR with unit tests
- [ ] <!-- {"checkboxId": "6ba7b810-9dad-11d1-80b4-00c04fd430c8", "radioGroupId": "utg-output-choice-group-unknown_comment_id"} --> Commit unit tests in branch `fix-pr-quality-gates`
</details>
</details>
<!-- finishing_touch_checkbox_end -->
<!-- tips_start -->
---
<sub>Comment `@coderabbitai help` to get the list of available commands and usage tips.</sub>
<!-- tips_end -->
<!-- internal state start -->
<!-- DwQgtGAEAqAWCWBnSTIEMB26CuAXA9mAOYCmGJATmriQCaQDG+Ats2bgFyQAOFk+AIwBWJBrngA3EsgEBPRvlqU0AgfFwA6NPEgQAfACgjoCEejqANiS4N4XRNwvqefAI7Y0T3PKLVpkADN8PmZBeCt0DHolRABrAm4DADlsZgFKLgAmADYADgMAVQAlABkuWFxcbkQOAHpaonVYbAENJmZagIt8AHdZMCcpWosnDFja7mwR2pz8gsQMyFxPWMR4WIMAZXxsCgYSSAEqDAZYLgD4AA8wXjB3T3V+3xpEA2g0ClJcQ+PTrmZtBgtstcNgavxuGQDEUSBJ4CQepRwQYSioSBZkQBhCgkPz0ahZAAMOTAhOyYAAjBToBSAOwcAAsAE4OBSmQAtIz6YzgKBkej4AI4AjEMjKGj0dpsDCcFz8YSicRSGTyJhKKiqdRaHTckxQOCoVCYYWEUjkKgShSsdhcKg9SCIVIAijyOQKdUqNSabS6MCGHmmAwaRq4ZoCWo9YKxLq9RATCh3DxeJ5+MAxeL4bgaWTMCwcAwAIiLBgAxCXIABBACSovNeIdTo+8kFjFgmFIr0K3Fo9dDBwA4uoABItStieD4DDIAAKRUg92TkGeB0jFGj3XtBEC+AYYP4GAszawfcg6YS6G43C4J9X696kAwaDYkXoAANJxpJiMAPo49zSTRuGoWBEFfB972WT4SG+V8hDjM9M1qAAqJCwIACloChM24eAMCISBYLjUI1CsZDUIASg0GBYAOIRBAdXAKGwMRdhXNBkFOds6AdfAlhoyBbxje0MHvJQLnIZA0AdXCiAiV8pAoeAAlkMC6IESA0NwxAaDQAUhQWICLQOV9iPCEgwMwN8EO4VTBEQciABoBIQCJYhIEgcLwviDmsyBRlwWpvEhU5RHGIIKABb5tI85BsCiSg+OoBQp3wJwe0tNSNCMIwy0rCwaAtCcpyWXiTyUBgLA+agiuQFsSEubhgktYIeBaJwGEgdh1HhTsoCSScSGynLywAWUwJSAMgAAxMzK0fQ8AC9KCMEpcP8Ti8LoLgAGpMlqMAAGYKSMABRbT4Ei7i1QOHE4QRTqAnC2URroeBUkLYsDAgMAjGDJoWgjKMhLjW4F0eYhU1Mqxs1zfMiwLUty2rWtxW4x1WCbfghQ2jsjArWglHxB97sHXAR3Uitx0nZBBI3B8n24lDABwCWdIAARSTR5IH7PwNJGsIrHIwBcAhQxLvkY+AiFIChaqwV8vwsX8SH/bSwNhdhkDQ99IXIWhXyc19EFkE5YCwjB4CW/WCJxTMxT18jtz4WdkEgr4ZIIgFcIsqI/Iu9RuK3HH/Di9UCLg2ooZIMjXyouAVyBumxLWyTpLwuSFKUlTIDUsXW1C2q8G8yAcUapyFlwWLuEgFD+qUDQ4MgTJCRQpyyBUKxkBQpgS7QBhYhblAp2WEZkCUHWlBOHqBKaAjZA+LAtOHixfQu5g8Hb8zB7DoiBfMpzLOLuLkFfOeKCwfywKCEZem4t0T/nx3Io4EK+5jobcorfLxRqkqi/KyrCrUyxp1BqTVuItUmAIdqnUZTdWkEYfq5AsoomTq2LitAdoHVpPtQkp1zqXUlIoG6sJ4T2hII9JqXAXq0DeswD6CMvp+gDHyH2LY0B4FNGKIyhDrQyltGge06NnSulVEQjUXptS+kMHqaihpJJYHYSKM0qMeHSllEoZYZlCFKEON0PuDYMYumLlxFU7plCam9DqJhBgADaABvAsxxSBVloAWDgjiuLfmyEyEgABWTIuR9jZFEAEAsDkCxAVDG4gsf1QwA1prGeMiYHjeAhjQNM0gMxZhzBYMJBZtIfFwKtcgbiKThP5MUkgpSyn5MbC6aJccBIJ16IATAIXaZgGOrZebBljpSkgfCWUskQCUoAcIO9AtxSWsmASch5ICs2XBpeWwFwTh2stHRyL4i6wTsmBBYVMsA9HYsXACTEWI4gmbxMEBwpJrDTsZDOylbLqUXriPSRdeAkJ2MgNe+V4BgBzuXbAVdQxJVwhVbAhN0Cnlegweskds6CA0Hk66AAhPRsRMQsEcPVR40S2A0NSAWAAvg5BxTiSAuOiRS78AQmRoDJISWkuRaQkGyL4vJkTYDRNiWGQGa5gZJLBqk5cYBI4w1yeEgpFAilrVKeUqIlS3FYKlXU2Q0SqwyiwrQZi/gpLkHtJiKsTSBV03CpABFztc5MWKrhbeEdd5W0Xp4DEMLx5kFsP4Ve68oGyH3j7Mg4V9jIH8u7A+4VIriC8i/VY+4TlWAkJgb4CsTkq2+OrGUiBkXhLRRirFzAcWXDxe4jcJKAC6zCYHvMUZwuslopQ2hhZoqw2iDhQJ3LEAxwjjGbVMddcRWofS6l5FaZg6hvzwFoIgJWd1ES0G/NK743IDAyMJL4/YTdchoC3YSBkB1fG0FpLQBkaA6UE23QwBghI4V5FpJkEghIDpMkyB1ZdMipTjsndO26pC6Dfn5FIldI7PnfjYFBb8Mbp2LsAwYOxBhICQALEgWc6KO10HzWo6c+BoquPOJ4BYDl4OIaQAAeQUopAmZA3GBHwyQQjCGCy0B3NpRSeEsUKTQM4mUlB5qbBBFUrgdjSVEYLNdIonp1AAHUsI0GnBQcwuArDUYCLR+jiHECwB2BYWgqG+6zmU6pkTNDaBFDigAER3Hx1jRBECYhon3ajjFsB0aM5O0zGAFNWDs6FRzTEXMMeM+5sz0gGCKW4OISc3mHN4YxP5xDow3K0CrIgR00grPUaLGpgslVtJRdiDCR0+VEDUZsURhDcGEOVcQzGpIDMMvBcQKF+A4WiqQDy2EsrlX8kgjBL55zamqsFnqo4TA1VJwZbyw6WIzXIT0CgFipQ4mLFtMgAgIgsBOlSGXkIzGqA25QLoNmzrDHQhKAy0cs+MkOtVYY8ESWuFPB5dq2wDLMQmstfG514TVWKs3dE/Z2Iz2BOIc82MgH12/sFNBMV68fmBtdeG5VR8EWMAZcaeIRTBwADkth7COGcLwecnNvBLj8Mgc1CKD7WSx+gS9uw/BzIPkwSeCw5lvcUukF2/FPZYCDlvE8Qdy5HZu4h07wOCwXfNnhCHg2cTM4uEQViBnYvw9u4pRo80nt1a4AWDHSmvvw9+4Nmr2vEMWYYCx927HlCkBl11qHvXYf9eO4hxHo2UcZf6oEOKBzyc7B9nagXbZNr0AuB3X+sJPAeBoKeZjEto34A46QKimxpuXndkxi38f8JMCT2D0Kwu/s4kQKlPARUMvSf9rHrP1m/d8BPAEH3KOflIDufhPszBf6IGqogZSRdc824OKGYvmntOF8G2L8788ruq8Q3djXj2AdA9e3H2vCMqvfcq0brrJuXs6+KYlyAyXUscXB7P7r1BHdLDhy7obDUkdjdRzrybcQZu31EOwhY4FfZjG4q35zNMoy24IcjsfEqAKaf4ABmgduJ2RCU+l20u5+8+D2FgWue+8WuEiWx+ABFYKW0giAai6+lWm+5Wt+u+4uJGhcLYmwTAkIbWweHYecDm5+DuMO1+zuIud+I2yO5ez+AOU2b+9A6QcK1y3+CWf+KWABIyOIwBPs5qoY4BUwy8kBAE4+XWk+OukuM+t+yBmuS+puBYOwuAJGAQNBtsdmJiuBCwKWhBX2RGZaWWOWuAs4oOGWmQtIAgN6TIDAtAFIDITKDIW6uQtAB0uQAQV6viuQmQB0AgPiR0AQhIAguQTIwRbICRaA0RzIaAvi9KIR2QPYWRuQ/i2QCMxKlaIGYGpAEGAO06AGw6EAJo34QE1yC6/GrRhSMGDiTh04n+dAFYuAMIs66GLAY6uAWKcUuAbihIZRQGDRNaTRvR7RNA/6Ps9RUAuEBU80SxJAM6SARU7RMqnREuikNAVK7ihIbIJAAgR6B0YA+wfhYAtI+6AgYA26R6aY2QAgaA5CAQuQAgFxDAJKlaGxPGng2xuxawk4Kxc2foQAA== -->
<!-- internal state end -->
coderabbitai[bot]
(Migrated from github.com)
reviewed 2026-06-11 17:56:15 +00:00
coderabbitai[bot]
(Migrated from github.com)
left a comment
Copy Link
Copy Source
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/pr-quality-gate-mobile.yml:
- Around line 19-25: Replace mutable action tags actions/checkout@v4 and
actions/setup-node@v4 with pinned commit SHAs and set persist-credentials: false
on the checkout step to reduce supply-chain and token exposure risk; update the
checkout step (actions/checkout) to include persist-credentials: false and
replace both uses entries (actions/checkout and actions/setup-node) with their
specific commit SHAs (use the official SHAs for the versions currently
referenced) so the workflow references immutable commits.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
Push a commit to this branch (recommended)
Create a new PR with the fixes
ℹ️ Review info⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: c764ac6d-9a10-4f74-8aa6-42ef51a52823
📥 Commits
Reviewing files that changed from the base of the PR and between 95f2362947 and 05ce208a8a.
📒 Files selected for processing (2)
.github/workflows/pr-quality-gate-desktop.yml
.github/workflows/pr-quality-gate-mobile.yml
**Actionable comments posted: 1**
<details>
<summary>🤖 Prompt for all review comments with AI agents</summary>
```
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/pr-quality-gate-mobile.yml:
- Around line 19-25: Replace mutable action tags actions/checkout@v4 and
actions/setup-node@v4 with pinned commit SHAs and set persist-credentials: false
on the checkout step to reduce supply-chain and token exposure risk; update the
checkout step (actions/checkout) to include persist-credentials: false and
replace both uses entries (actions/checkout and actions/setup-node) with their
specific commit SHAs (use the official SHAs for the versions currently
referenced) so the workflow references immutable commits.
```
</details>
<details>
<summary>🪄 Autofix (Beta)</summary>
Fix all unresolved CodeRabbit comments on this PR:
- [ ] <!-- {"checkboxId": "4b0d0e0a-96d7-4f10-b296-3a18ea78f0b9"} --> Push a commit to this branch (recommended)
- [ ] <!-- {"checkboxId": "ff5b1114-7d8c-49e6-8ac1-43f82af23a33"} --> Create a new PR with the fixes
</details>
---
<details>
<summary>ℹ️ Review info</summary>
<details>
<summary>⚙️ Run configuration</summary>
**Configuration used**: defaults
**Review profile**: CHILL
**Plan**: Pro Plus
**Run ID**: `c764ac6d-9a10-4f74-8aa6-42ef51a52823`
</details>
<details>
<summary>📥 Commits</summary>
Reviewing files that changed from the base of the PR and between 95f2362947076cea50ee50ef615e654ef1e0d45c and 05ce208a8a0435d7d4af9dda8cc0ca6872e0392c.
</details>
<details>
<summary>📒 Files selected for processing (2)</summary>
* `.github/workflows/pr-quality-gate-desktop.yml`
* `.github/workflows/pr-quality-gate-mobile.yml`
</details>
</details>
<!-- This is an auto-generated comment by CodeRabbit for review status -->
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-quality-gate-mobile.yml"# Show file with line numbers around the referenced area
nl -ba "$FILE"| sed -n '1,120p'# Also scan for other uses of actions/checkout and actions/setup-node in the repo for consistency
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows ||true
Repository: flowy-live/llink
Length of output: 103
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-quality-gate-mobile.yml"if[ ! -f "$FILE"];thenecho"Missing file: $FILE"exit1fi
nl -ba "$FILE"| sed -n '1,160p'echo"---- other workflows using checkout/setup-node ----"
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows ||trueecho"---- check for persist-credentials usage ----"
rg -n "persist-credentials" .github/workflows ||true
Repository: flowy-live/llink
Length of output: 104
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-quality-gate-mobile.yml"
nl -ba "$FILE"| sed -n '1,200p'echo"---- other workflows using checkout/setup-node ----"
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows ||trueecho"---- check for persist-credentials usage ----"
rg -n "persist-credentials" .github/workflows ||true
Repository: flowy-live/llink
Length of output: 103
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-quality-gate-mobile.yml"echo"=== pr-quality-gate-mobile.yml (lines 1-200) ==="if[ -f "$FILE"];then
cat -n "$FILE"| sed -n '1,200p'elseecho"Missing $FILE"exit1fiecho"=== other workflows using checkout/setup-node (pinned or tag refs) ==="
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows ||trueecho"=== persist-credentials occurrences ==="
rg -n "persist-credentials" .github/workflows ||true
Repository: flowy-live/llink
Length of output: 1941
Pin actions to commit SHAs and disable persisted checkout credentials in CI
.github/workflows/pr-quality-gate-mobile.yml uses mutable tag refs (actions/checkout@v4 at line 20, actions/setup-node@v4 at line 23) and the checkout step does not set persist-credentials: false, increasing supply-chain and token exposure risk.
[warning] 19-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 23-23: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/pr-quality-gate-mobile.yml around lines 19 - 25, Replace
mutable action tags actions/checkout@v4 and actions/setup-node@v4 with pinned
commit SHAs and set persist-credentials: false on the checkout step to reduce
supply-chain and token exposure risk; update the checkout step
(actions/checkout) to include persist-credentials: false and replace both uses
entries (actions/checkout and actions/setup-node) with their specific commit
SHAs (use the official SHAs for the versions currently referenced) so the
workflow references immutable commits.
Source: Linters/SAST tools
_⚠️ Potential issue_ | _🟠 Major_
<details>
<summary>🧩 Analysis chain</summary>
🏁 Script executed:
```shell
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-quality-gate-mobile.yml"
# Show file with line numbers around the referenced area
nl -ba "$FILE" | sed -n '1,120p'
# Also scan for other uses of actions/checkout and actions/setup-node in the repo for consistency
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true
```
Repository: flowy-live/llink
Length of output: 103
---
🏁 Script executed:
```shell
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-quality-gate-mobile.yml"
if [ ! -f "$FILE" ]; then
echo "Missing file: $FILE"
exit 1
fi
nl -ba "$FILE" | sed -n '1,160p'
echo "---- other workflows using checkout/setup-node ----"
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true
echo "---- check for persist-credentials usage ----"
rg -n "persist-credentials" .github/workflows || true
```
Repository: flowy-live/llink
Length of output: 104
---
🏁 Script executed:
```shell
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-quality-gate-mobile.yml"
nl -ba "$FILE" | sed -n '1,200p'
echo "---- other workflows using checkout/setup-node ----"
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true
echo "---- check for persist-credentials usage ----"
rg -n "persist-credentials" .github/workflows || true
```
Repository: flowy-live/llink
Length of output: 103
---
🏁 Script executed:
```shell
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/pr-quality-gate-mobile.yml"
echo "=== pr-quality-gate-mobile.yml (lines 1-200) ==="
if [ -f "$FILE" ]; then
cat -n "$FILE" | sed -n '1,200p'
else
echo "Missing $FILE"
exit 1
fi
echo "=== other workflows using checkout/setup-node (pinned or tag refs) ==="
rg -n "uses:\s*actions/(checkout|setup-node)@" .github/workflows || true
echo "=== persist-credentials occurrences ==="
rg -n "persist-credentials" .github/workflows || true
```
Repository: flowy-live/llink
Length of output: 1941
---
</details>
**Pin actions to commit SHAs and disable persisted checkout credentials in CI**
`.github/workflows/pr-quality-gate-mobile.yml` uses mutable tag refs (`actions/checkout@v4` at line 20, `actions/setup-node@v4` at line 23) and the checkout step does not set `persist-credentials: false`, increasing supply-chain and token exposure risk.
<details>
<summary>Suggested hardening diff</summary>
```diff
- name: Check out repository code
- uses: actions/checkout@v4
+ uses: actions/checkout@<FULL_COMMIT_SHA>
+ with:
+ persist-credentials: false
- name: Set up Node.js
- uses: actions/setup-node@v4
+ uses: actions/setup-node@<FULL_COMMIT_SHA>
with:
node-version: '20'
```
</details>
<details>
<summary>🧰 Tools</summary>
<details>
<summary>🪛 zizmor (1.25.2)</summary>
[warning] 19-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
---
[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
---
[error] 23-23: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
</details>
</details>
<details>
<summary>🤖 Prompt for AI Agents</summary>
```
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/pr-quality-gate-mobile.yml around lines 19 - 25, Replace
mutable action tags actions/checkout@v4 and actions/setup-node@v4 with pinned
commit SHAs and set persist-credentials: false on the checkout step to reduce
supply-chain and token exposure risk; update the checkout step
(actions/checkout) to include persist-credentials: false and replace both uses
entries (actions/checkout and actions/setup-node) with their specific commit
SHAs (use the official SHAs for the versions currently referenced) so the
workflow references immutable commits.
```
</details>
<!-- fingerprinting:phantom:poseidon:hawk -->
<!-- cr-comment:v1:d1e53b8162f207c4b8c489fe -->
_Source: Linters/SAST tools_
<!-- This is an auto-generated comment by CodeRabbit -->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary by CodeRabbit
📝 Walkthrough
Walkthrough
The PR separates the PR quality gate workflows by platform: the desktop workflow is narrowed to desktop-only changes, and a new mobile-specific workflow is created to enforce the same lint and format checks for mobile code independently.
Changes
Platform-specific CI workflows
.github/workflows/pr-quality-gate-desktop.yml,.github/workflows/pr-quality-gate-mobile.ymljs/desktop/**changes with a singleverifyjob; new mobile workflow created to independently enforceyarn lintandyarn format:checkonjs/mobile/**changes, both using Node.js 20 with immutable dependency installation.Estimated code review effort
🎯 2 (Simple) | ⏱️ ~8 minutes
Poem
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings.
✨ Finishing Touches
🧪 Generate unit tests (beta)
fix-pr-quality-gatesComment
@coderabbitai helpto get the list of available commands and usage tips.Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID:
c764ac6d-9a10-4f74-8aa6-42ef51a52823📥 Commits
Reviewing files that changed from the base of the PR and between
95f2362947and05ce208a8a.📒 Files selected for processing (2)
.github/workflows/pr-quality-gate-desktop.yml.github/workflows/pr-quality-gate-mobile.yml@@ -0,0 +22,4 @@- name: Set up Node.jsuses: actions/setup-node@v4with:node-version: '20'⚠️ Potential issue | 🟠 Major
🧩 Analysis chain
🏁 Script executed:
Repository: flowy-live/llink
Length of output: 103
🏁 Script executed:
Repository: flowy-live/llink
Length of output: 104
🏁 Script executed:
Repository: flowy-live/llink
Length of output: 103
🏁 Script executed:
Repository: flowy-live/llink
Length of output: 1941
Pin actions to commit SHAs and disable persisted checkout credentials in CI
.github/workflows/pr-quality-gate-mobile.ymluses mutable tag refs (actions/checkout@v4at line 20,actions/setup-node@v4at line 23) and the checkout step does not setpersist-credentials: false, increasing supply-chain and token exposure risk.Suggested hardening diff
🧰 Tools
🪛 zizmor (1.25.2)
[warning] 19-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 23-23: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Source: Linters/SAST tools