nickofthyme/Checkout node setup

Checkout, setup and install node with dependencies

View on GitHub

Trust Signals

Scorecard Score
Scorecard 2–4scored Jul 6, 2026
Maintenance Recency
Stalelast commit Mar 23, 2023
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: nickofthyme/checkout-node-setup@fd73010e8ea31fc4b00acbe8c1496e51e7bf3739 # v2.0.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
skip-checkoutSkip checkout stepnofalse
skip-setup-nodeSkip node setup stepnofalse
skip-npm-installSkip npm install stepnofalse
checkout-tokenPersonal access token (PAT) used to fetch the repository. The PAT is configured with the local git config, which enables your scripts to run authenticated git commands. The post-job step removes the PAT. We recommend using a service account with the least permissions necessary. Also when generating a new PAT, select the least scopes necessary. [Learn more about creating and using encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) no${{ github.token }}
setup-node-tokenUsed to pull node distributions from node-versions. Since there's a default, this is typically not supplied by the user.no${{ github.token }}
repositoryRepository name with owner. For example, actions/checkoutno${{ github.repository }}
refThe branch, tag or SHA to checkout. When checking out the repository that triggered a workflow, this defaults to the reference or SHA for that event. Otherwise, uses the default branch. no
ssh-keySSH key used to fetch the repository. The SSH key is configured with the local git config, which enables your scripts to run authenticated git commands. The post-job step removes the SSH key. We recommend using a service account with the least permissions necessary. [Learn more about creating and using encrypted secrets](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets) no
ssh-known-hostsKnown hosts in addition to the user and global host key database. The public SSH keys for a host may be obtained using the utility `ssh-keyscan`. For example, `ssh-keyscan github.com`. The public key for github.com is always implicitly added. no
ssh-strictWhether to perform strict host key checking. When true, adds the options `StrictHostKeyChecking=yes` and `CheckHostIP=no` to the SSH command line. Use the input `ssh-known-hosts` to configure additional hosts. notrue
persist-credentialsWhether to configure the token or SSH key with the local git confignofalse
pathRelative path under $GITHUB_WORKSPACE to place the repositoryno
cleanWhether to execute `git clean -ffdx && git reset --hard HEAD` before fetchingnotrue
fetch-depthNumber of commits to fetch. 0 indicates all history for all branches and tags.no1
lfsWhether to download Git-LFS filesnofalse
submodulesWhether to checkout submodules: `true` to checkout submodules or `recursive` to recursively checkout submodules. When the `ssh-key` input is not provided, SSH URLs beginning with `git@github.com:` are converted to HTTPS. nofalse
always-authSet always-auth in npmrcnofalse
node-versionVersion Spec of the version to use. Examples: 12.x, 10.15.1, >=10.15.0no
node-version-fileFile containing the version Spec of the version to use. Examples: .nvmrc, .node-versionno
architectureTarget architecture for Node to use. Examples: x86, x64. Will use system architecture by default.no
check-latestSet this option if you want the action to check for the latest available version that satisfies the version specnofalse
registry-urlOptional registry to set up for auth. Will set the registry in a project level .npmrc and .yarnrc file, and set up auth to read in from env.NODE_AUTH_TOKENno
scopeOptional scope for authenticating against scoped registriesno
cacheUsed to specify a package manager for caching in the default directory. Supported values: npm, yarn, pnpmno
cache-dependency-pathUsed to specify the path to a dependency file: package-lock.json, yarn.lock, etc. Supports wildcards or a list of file names for caching multiple dependencies.no
working-directoryWorking directory to specify subfolder in which dependencies are definedno
useLockFileOption to enable or disable use of a lock file (package-lock.json/yarn.lock)no
useRollingCacheOption to enable restoring a cache that doesn't exactly match the lockfile, and expire once a month to keep it from only growing largernotrue
install-commandCustom install command to useno

no outputs