Skip to content

Commit d6d4e5e

Browse files
Open release pull requests as a GitHub App so their checks run
1 parent 39ee40f commit d6d4e5e

1 file changed

Lines changed: 44 additions & 42 deletions

File tree

‎.github/workflows/sqlite3mc-release.yml‎

Lines changed: 44 additions & 42 deletions
Original file line numberDiff line numberDiff line change
@@ -5,83 +5,88 @@ name: SQLite3MC release
55
schedule:
66
- cron: "17 5 * * *"
77
workflow_dispatch:
8+
inputs:
9+
version:
10+
description: SQLite3MC release to vendor, such as 2.5.2. Empty means the latest.
11+
required: false
12+
type: string
813

14+
# Every write goes through the app token, so the workflow token stays read-only.
915
permissions:
10-
contents: write
11-
pull-requests: write
16+
contents: read
1217

1318
concurrency:
1419
group: ${{ github.workflow }}
1520
cancel-in-progress: false
1621

17-
env:
18-
CARGO_TERM_COLOR: always
19-
2022
jobs:
2123
vendor:
22-
name: Vendor the latest SQLite3MC release
24+
name: Vendor a SQLite3MC release
2325
runs-on: ubuntu-latest
2426
timeout-minutes: 30
2527
steps:
2628
# A manual dispatch may select another ref, and only main's tree belongs here.
2729
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2830
with:
2931
ref: main
32+
persist-credentials: false
3033

31-
- name: Compare the pinned and the latest release
34+
- name: Pick the release
3235
id: release
3336
env:
3437
GH_TOKEN: ${{ github.token }}
38+
REQUESTED: ${{ inputs.version }}
3539
run: |
3640
set -euo pipefail
37-
latest=$(gh release view --repo utelle/SQLite3MultipleCiphers --json tagName --jq '.tagName | ltrimstr("v")')
3841
pinned=$(sed -nE 's/^pub const SQLITE3MC_VERSION: &str = "(.*)";$/\1/p' src/lib.rs)
39-
echo "latest=$latest" >> "$GITHUB_OUTPUT"
40-
newest=$(printf '%s\n%s\n' "$pinned" "$latest" | sort -V | tail -n 1)
41-
if [ "$latest" != "$pinned" ] && [ "$newest" = "$latest" ]; then
42-
echo "moved=yes" >> "$GITHUB_OUTPUT"
42+
if [ -n "$REQUESTED" ]; then
43+
target=$REQUESTED
44+
[ "$target" != "$pinned" ] && echo "moved=yes" >> "$GITHUB_OUTPUT"
45+
else
46+
target=$(gh release view --repo utelle/SQLite3MultipleCiphers --json tagName --jq '.tagName | ltrimstr("v")')
47+
newest=$(printf '%s\n%s\n' "$pinned" "$target" | sort -V | tail -n 1)
48+
if [ "$target" != "$pinned" ] && [ "$newest" = "$target" ]; then
49+
echo "moved=yes" >> "$GITHUB_OUTPUT"
50+
fi
4351
fi
44-
echo "pinned $pinned, latest $latest"
52+
echo "target=$target" >> "$GITHUB_OUTPUT"
53+
echo "pinned $pinned, target $target"
4554
4655
- if: steps.release.outputs.moved == 'yes'
4756
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
4857

4958
- if: steps.release.outputs.moved == 'yes'
50-
run: |
51-
rustup toolchain install stable --profile minimal --component rustfmt --component clippy
52-
rustup toolchain install 1.81 --profile minimal
53-
54-
- if: steps.release.outputs.moved == 'yes'
55-
run: ./bump.sh "${{ steps.release.outputs.latest }}"
59+
env:
60+
TARGET: ${{ steps.release.outputs.target }}
61+
run: ./bump.sh "$TARGET"
5662

57-
# A pull request opened with GITHUB_TOKEN starts no workflow, so the gate runs here.
63+
# A pull request from the app, unlike one from the workflow token, starts CI, CodeQL,
64+
# Coverage and Sonar on it, and so does every later push to its branch.
5865
- if: steps.release.outputs.moved == 'yes'
59-
run: |
60-
set -euo pipefail
61-
cargo +stable fmt --check
62-
cargo +stable clippy --all-targets -- -D warnings
63-
RUSTDOCFLAGS="-D warnings" cargo +stable doc --no-deps
64-
cargo +stable test --all-targets
65-
cargo +stable test --doc
66-
cargo +1.81 test --all-targets
67-
cargo +stable package --allow-dirty
68-
crate=$(echo target/package/sqlite3mc-src-*.crate)
69-
dir=$(basename "$crate" .crate)
70-
tar -xzf "$crate" -C target/package
71-
cp -r smoke "target/package/$dir/smoke"
72-
cargo +stable run --manifest-path "target/package/$dir/smoke/Cargo.toml"
66+
name: Mint an app token
67+
id: app-token
68+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
69+
with:
70+
client-id: ${{ secrets.RELEASE_APP_CLIENT_ID }}
71+
private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }}
72+
permission-contents: write
73+
permission-pull-requests: write
7374

7475
- if: steps.release.outputs.moved == 'yes'
76+
name: Open the pull request
7577
env:
76-
GH_TOKEN: ${{ github.token }}
77-
VERSION: ${{ steps.release.outputs.latest }}
78+
GH_TOKEN: ${{ steps.app-token.outputs.token }}
79+
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
80+
VERSION: ${{ steps.release.outputs.target }}
7881
run: |
7982
set -euo pipefail
8083
sqlite=$(sed -nE 's/^pub const SQLITE_VERSION: &str = "(.*)";$/\1/p' src/lib.rs)
8184
branch="sqlite3mc/v$VERSION"
8285
title="Vendor SQLite3MC $VERSION on SQLite $sqlite"
83-
git config user.name "github-actions[bot]"
84-
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
86+
bot_id=$(gh api "/users/${APP_SLUG}%5Bbot%5D" --jq .id)
87+
git config user.name "${APP_SLUG}[bot]"
88+
git config user.email "${bot_id}+${APP_SLUG}[bot]@users.noreply.github.com"
89+
git remote set-url origin "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git"
8590
git checkout -b "$branch"
8691
git add Cargo.toml Cargo.lock smoke/Cargo.lock upgrade.sh src/lib.rs sqlite3mc
8792
git commit -m "$title"
@@ -98,7 +103,4 @@ jobs:
98103
gh pr view "$branch" --json number >/dev/null 2>&1 || gh pr create \
99104
--base main --head "$branch" \
100105
--title "$title" \
101-
--body "$(printf '%s\n' \
102-
"SQLite3MC $VERSION, from https://github.com/utelle/SQLite3MultipleCiphers/releases/tag/v$VERSION. The archive's checksum was taken from the release's SHA256SUMS after its Sigstore signature verified against SQLite3MC's own release workflow, and the vendored files were extracted from the archive unchanged." \
103-
'' \
104-
'fmt, clippy, the tests on stable and 1.81 and cargo package passed in the job that opened this. A pull request opened by the workflow token starts no other workflow, so close and reopen it to run CI, CodeQL, Coverage and Sonar here.')"
106+
--body "SQLite3MC $VERSION, from https://github.com/utelle/SQLite3MultipleCiphers/releases/tag/v$VERSION. The archive's checksum was taken from the release's SHA256SUMS after its Sigstore signature verified against SQLite3MC's own release workflow, and the vendored files were extracted from the archive unchanged."

0 commit comments

Comments
 (0)