@@ -5,83 +5,88 @@ name: SQLite3MC release
55 schedule :
66 - cron : " 17 5 * * *"
77 workflow_dispatch :
8+ inputs :
9+ version :
10+ description : SQLite3MC release to vendor, such as 2.5.2. Empty means the latest.
11+ required : false
12+ type : string
813
14+ # Every write goes through the app token, so the workflow token stays read-only.
915permissions :
10- contents : write
11- pull-requests : write
16+ contents : read
1217
1318concurrency :
1419 group : ${{ github.workflow }}
1520 cancel-in-progress : false
1621
17- env :
18- CARGO_TERM_COLOR : always
19-
2022jobs :
2123 vendor :
22- name : Vendor the latest SQLite3MC release
24+ name : Vendor a SQLite3MC release
2325 runs-on : ubuntu-latest
2426 timeout-minutes : 30
2527 steps :
2628 # A manual dispatch may select another ref, and only main's tree belongs here.
2729 - uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2830 with :
2931 ref : main
32+ persist-credentials : false
3033
31- - name : Compare the pinned and the latest release
34+ - name : Pick the release
3235 id : release
3336 env :
3437 GH_TOKEN : ${{ github.token }}
38+ REQUESTED : ${{ inputs.version }}
3539 run : |
3640 set -euo pipefail
37- latest=$(gh release view --repo utelle/SQLite3MultipleCiphers --json tagName --jq '.tagName | ltrimstr("v")')
3841 pinned=$(sed -nE 's/^pub const SQLITE3MC_VERSION: &str = "(.*)";$/\1/p' src/lib.rs)
39- echo "latest=$latest" >> "$GITHUB_OUTPUT"
40- newest=$(printf '%s\n%s\n' "$pinned" "$latest" | sort -V | tail -n 1)
41- if [ "$latest" != "$pinned" ] && [ "$newest" = "$latest" ]; then
42- echo "moved=yes" >> "$GITHUB_OUTPUT"
42+ if [ -n "$REQUESTED" ]; then
43+ target=$REQUESTED
44+ [ "$target" != "$pinned" ] && echo "moved=yes" >> "$GITHUB_OUTPUT"
45+ else
46+ target=$(gh release view --repo utelle/SQLite3MultipleCiphers --json tagName --jq '.tagName | ltrimstr("v")')
47+ newest=$(printf '%s\n%s\n' "$pinned" "$target" | sort -V | tail -n 1)
48+ if [ "$target" != "$pinned" ] && [ "$newest" = "$target" ]; then
49+ echo "moved=yes" >> "$GITHUB_OUTPUT"
50+ fi
4351 fi
44- echo "pinned $pinned, latest $latest"
52+ echo "target=$target" >> "$GITHUB_OUTPUT"
53+ echo "pinned $pinned, target $target"
4554
4655 - if : steps.release.outputs.moved == 'yes'
4756 uses : sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
4857
4958 - if : steps.release.outputs.moved == 'yes'
50- run : |
51- rustup toolchain install stable --profile minimal --component rustfmt --component clippy
52- rustup toolchain install 1.81 --profile minimal
53-
54- - if : steps.release.outputs.moved == 'yes'
55- run : ./bump.sh "${{ steps.release.outputs.latest }}"
59+ env :
60+ TARGET : ${{ steps.release.outputs.target }}
61+ run : ./bump.sh "$TARGET"
5662
57- # A pull request opened with GITHUB_TOKEN starts no workflow, so the gate runs here.
63+ # A pull request from the app, unlike one from the workflow token, starts CI, CodeQL,
64+ # Coverage and Sonar on it, and so does every later push to its branch.
5865 - if : steps.release.outputs.moved == 'yes'
59- run : |
60- set -euo pipefail
61- cargo +stable fmt --check
62- cargo +stable clippy --all-targets -- -D warnings
63- RUSTDOCFLAGS="-D warnings" cargo +stable doc --no-deps
64- cargo +stable test --all-targets
65- cargo +stable test --doc
66- cargo +1.81 test --all-targets
67- cargo +stable package --allow-dirty
68- crate=$(echo target/package/sqlite3mc-src-*.crate)
69- dir=$(basename "$crate" .crate)
70- tar -xzf "$crate" -C target/package
71- cp -r smoke "target/package/$dir/smoke"
72- cargo +stable run --manifest-path "target/package/$dir/smoke/Cargo.toml"
66+ name : Mint an app token
67+ id : app-token
68+ uses : actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
69+ with :
70+ client-id : ${{ secrets.RELEASE_APP_CLIENT_ID }}
71+ private-key : ${{ secrets.RELEASE_APP_PRIVATE_KEY }}
72+ permission-contents : write
73+ permission-pull-requests : write
7374
7475 - if : steps.release.outputs.moved == 'yes'
76+ name : Open the pull request
7577 env :
76- GH_TOKEN : ${{ github.token }}
77- VERSION : ${{ steps.release.outputs.latest }}
78+ GH_TOKEN : ${{ steps.app-token.outputs.token }}
79+ APP_SLUG : ${{ steps.app-token.outputs.app-slug }}
80+ VERSION : ${{ steps.release.outputs.target }}
7881 run : |
7982 set -euo pipefail
8083 sqlite=$(sed -nE 's/^pub const SQLITE_VERSION: &str = "(.*)";$/\1/p' src/lib.rs)
8184 branch="sqlite3mc/v$VERSION"
8285 title="Vendor SQLite3MC $VERSION on SQLite $sqlite"
83- git config user.name "github-actions[bot]"
84- git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
86+ bot_id=$(gh api "/users/${APP_SLUG}%5Bbot%5D" --jq .id)
87+ git config user.name "${APP_SLUG}[bot]"
88+ git config user.email "${bot_id}+${APP_SLUG}[bot]@users.noreply.github.com"
89+ git remote set-url origin "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git"
8590 git checkout -b "$branch"
8691 git add Cargo.toml Cargo.lock smoke/Cargo.lock upgrade.sh src/lib.rs sqlite3mc
8792 git commit -m "$title"
98103 gh pr view "$branch" --json number >/dev/null 2>&1 || gh pr create \
99104 --base main --head "$branch" \
100105 --title "$title" \
101- --body "$(printf '%s\n' \
102- "SQLite3MC $VERSION, from https://github.com/utelle/SQLite3MultipleCiphers/releases/tag/v$VERSION. The archive's checksum was taken from the release's SHA256SUMS after its Sigstore signature verified against SQLite3MC's own release workflow, and the vendored files were extracted from the archive unchanged." \
103- '' \
104- 'fmt, clippy, the tests on stable and 1.81 and cargo package passed in the job that opened this. A pull request opened by the workflow token starts no other workflow, so close and reopen it to run CI, CodeQL, Coverage and Sonar here.')"
106+ --body "SQLite3MC $VERSION, from https://github.com/utelle/SQLite3MultipleCiphers/releases/tag/v$VERSION. The archive's checksum was taken from the release's SHA256SUMS after its Sigstore signature verified against SQLite3MC's own release workflow, and the vendored files were extracted from the archive unchanged."
0 commit comments