Skip to content

Commit 6df3c2b

Browse files
authored
Merge pull request #48 from LibreCodeCoop/fix/materialized-workflow-sync
ci: restore materialized workflow synchronization
2 parents b5083d7 + 41b8c3b commit 6df3c2b

11 files changed

Lines changed: 526 additions & 24 deletions

‎consumers.json‎

Lines changed: 0 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,20 +1,5 @@
11
{
22
"consumers": [
3-
{
4-
"repository": "LibreCodeCoop/extract",
5-
"workflows": [
6-
"block-unconventional-commits.yml",
7-
"lint-eslint.yml",
8-
"lint-info-xml.yml",
9-
"lint-php-cs.yml",
10-
"lint-php.yml",
11-
"lint-stylelint.yml",
12-
"npm-build.yml",
13-
"openapi.yml",
14-
"psalm.yml",
15-
"reuse.yml"
16-
]
17-
},
183
{
194
"repository": "LibreCodeCoop/profile_fields",
205
"workflows": [
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
--- upstream/vendor/nextcloud/lint-eslint.yml
2+
+++ workflow-templates/lint-eslint.yml
3+
@@ -1,9 +1,9 @@
4+
# This workflow is provided via the organization template repository
5+
#
6+
-# https://github.com/nextcloud/.github
7+
+# https://github.com/LibreCodeCoop/.github
8+
# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization
9+
#
10+
# SPDX-FileCopyrightText: 2021-2024 Nextcloud GmbH and Nextcloud contributors
11+
# SPDX-License-Identifier: MIT
12+
13+
name: Lint eslint
14+
@@ -19,7 +19,7 @@
15+
16+
jobs:
17+
changes:
18+
- runs-on: ubuntu-latest-low
19+
+ runs-on: ubuntu-latest
20+
permissions:
21+
contents: read
22+
pull-requests: read
23+
@@ -87,7 +87,7 @@
24+
summary:
25+
permissions:
26+
contents: none
27+
- runs-on: ubuntu-latest-low
28+
+ runs-on: ubuntu-latest
29+
needs: [changes, lint]
30+
31+
if: always()
Lines changed: 70 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,70 @@
1+
--- upstream/vendor/nextcloud/sync-workflow-templates.yml
2+
+++ workflow-templates/sync-workflow-templates.yml
3+
@@ -1,9 +1,9 @@
4+
# This workflow is provided via the organization template repository
5+
#
6+
-# https://github.com/nextcloud/.github
7+
+# https://github.com/LibreCodeCoop/.github
8+
# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization
9+
#
10+
# SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors
11+
# SPDX-License-Identifier: MIT
12+
13+
# This workflow will update all workflow templates
14+
@@ -42,12 +42,24 @@
15+
with:
16+
require: admin
17+
18+
+ - name: Create GitHub App token
19+
+ id: app-token
20+
+ uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4
21+
+ with:
22+
+ app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
23+
+ private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}
24+
+ owner: LibreCodeCoop
25+
+ repositories: ${{ github.event.repository.name }}
26+
+ permission-contents: write
27+
+ permission-pull-requests: write
28+
+ permission-workflows: write
29+
+
30+
- name: Checkout workflow repository
31+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
32+
with:
33+
persist-credentials: false
34+
path: source
35+
- repository: nextcloud/.github
36+
+ repository: LibreCodeCoop/.github
37+
38+
- name: Checkout app
39+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
40+
@@ -78,7 +90,7 @@
41+
echo "ℹ️ Locked version: $locked_version"
42+
echo "ℹ️ Current version: $new_version"
43+
echo "🆙 Updating existing workflow: $filename"
44+
- echo "- 🆙 Updated [$filename](https://github.com/nextcloud/.github/commits/master/workflow-templates/$filename)" >> $GITHUB_ENV
45+
+ echo "- 🆙 Updated [$filename](https://github.com/LibreCodeCoop/.github/commits/main/workflow-templates/$filename)" >> $GITHUB_ENV
46+
47+
cp "$workflow" "$target_file"
48+
49+
@@ -123,10 +135,10 @@
50+
- name: Create Pull Request
51+
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
52+
with:
53+
- token: ${{ secrets.COMMAND_BOT_WORKFLOWS }}
54+
+ token: ${{ steps.app-token.outputs.token }}
55+
commit-message: 'ci(actions): Update workflow templates from organization template repository'
56+
committer: GitHub <noreply@github.com>
57+
- author: nextcloud-command <nextcloud-command@users.noreply.github.com>
58+
+ author: librecode-workflow-automation[bot] <331658022+librecode-workflow-automation[bot]@users.noreply.github.com>
59+
path: target
60+
signoff: true
61+
branch: 'automated/noid/${{ matrix.branches }}-update-workflows'
62+
@@ -134,7 +146,7 @@
63+
draft: ${{ env.DRAFT_ONLY == 1 }}
64+
add-paths: .github/workflows/*.yml,.github/actions-lock.txt
65+
body: |
66+
- Automated update of all workflow templates from [nextcloud/.github](https://github.com/nextcloud/.github)
67+
+ Automated update of all workflow templates from [LibreCodeCoop/.github](https://github.com/LibreCodeCoop/.github)
68+
${{ env.SUMMARY }}
69+
labels: |
70+
dependencies

‎upstream/sources.json‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,15 @@
116116
"url": "https://raw.githubusercontent.com/nextcloud/.github/98dc00f32e5c4b85361a06a40c7f8d7d1c0a38f3/workflow-templates/reuse.yml",
117117
"sha256": "13133274d505be2d100b27637ccd893a24f9dea82cbf96483a1024138aacf5b3",
118118
"destination": "upstream/vendor/nextcloud/reuse.yml"
119+
},
120+
{
121+
"name": "nextcloud-sync-workflow-templates",
122+
"repository": "nextcloud/.github",
123+
"ref": "master",
124+
"path": "workflow-templates/sync-workflow-templates.yml",
125+
"url": "https://raw.githubusercontent.com/nextcloud/.github/e137952600ed786d2dfd1bf928fadf92d295483c/workflow-templates/sync-workflow-templates.yml",
126+
"sha256": "b1a49a5dbc35ca40a1485bed5f84ef042c6c738f5c81cb229035f24fd6dc0cf0",
127+
"destination": "upstream/vendor/nextcloud/sync-workflow-templates.yml"
119128
}
120129
]
121130
}

‎upstream/templates.json‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,22 @@
103103
"patches/nextcloud/reuse.yml.patch"
104104
],
105105
"destination": ".github/workflows/reuse.yml"
106+
},
107+
{
108+
"name": "nextcloud-lint-eslint-template",
109+
"source": "upstream/vendor/nextcloud/lint-eslint.yml",
110+
"patches": [
111+
"patches/nextcloud/lint-eslint-template.yml.patch"
112+
],
113+
"destination": "workflow-templates/lint-eslint.yml"
114+
},
115+
{
116+
"name": "nextcloud-sync-workflow-templates",
117+
"source": "upstream/vendor/nextcloud/sync-workflow-templates.yml",
118+
"patches": [
119+
"patches/nextcloud/sync-workflow-templates.yml.patch"
120+
],
121+
"destination": "workflow-templates/sync-workflow-templates.yml"
106122
}
107123
]
108124
}
Lines changed: 141 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,141 @@
1+
# This workflow is provided via the organization template repository
2+
#
3+
# https://github.com/nextcloud/.github
4+
# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization
5+
#
6+
# SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors
7+
# SPDX-License-Identifier: MIT
8+
9+
# This workflow will update all workflow templates
10+
# Additionally it will reapply `workflow.yml.patch` files after syncing and only then commit the result
11+
name: Update workflows
12+
on:
13+
workflow_dispatch:
14+
schedule:
15+
- cron: "5 2 * * 0"
16+
17+
permissions:
18+
contents: read
19+
20+
jobs:
21+
dispatch:
22+
runs-on: ubuntu-latest
23+
24+
strategy:
25+
fail-fast: false
26+
matrix:
27+
branches:
28+
- ${{ github.event.repository.default_branch }}
29+
- 'stable35'
30+
- 'stable34'
31+
- 'stable33'
32+
33+
name: Update workflows in ${{ matrix.branches }}
34+
35+
permissions:
36+
contents: write
37+
pull-requests: write
38+
39+
steps:
40+
- name: Check actor permission
41+
uses: skjnldsv/check-actor-permission@69e92a3c4711150929bca9fcf34448c5bf5526e7 # v3.0
42+
with:
43+
require: admin
44+
45+
- name: Checkout workflow repository
46+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
47+
with:
48+
persist-credentials: false
49+
path: source
50+
repository: nextcloud/.github
51+
52+
- name: Checkout app
53+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
54+
with:
55+
persist-credentials: false
56+
path: target
57+
ref: ${{ matrix.branches }}
58+
59+
- name: Copy all workflow templates
60+
run: |
61+
echo 'SUMMARY<<EOF' >> $GITHUB_ENV
62+
draft_only=0
63+
for workflow in ./source/workflow-templates/*.yml; do
64+
echo "❓ Looking for $workflow"
65+
if [ -f "$workflow" ]; then
66+
filename=$(basename "$workflow")
67+
target_file="./target/.github/workflows/$filename"
68+
69+
# Only copy if the file exists in the target repository
70+
if [ -f "$target_file" ]; then
71+
if [ -f "./target/.github/actions-lock.txt" ]; then
72+
locked_version=$(grep " $filename" ./target/.github/actions-lock.txt | cat)
73+
else
74+
echo "# SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors" >> ./target/.github/actions-lock.txt
75+
echo "# SPDX-License""-Identifier: MIT" >> ./target/.github/actions-lock.txt
76+
locked_version=""
77+
fi
78+
locked_version=$(echo $locked_version | cut -f 1 -d " ")
79+
new_version=$(md5sum $workflow | cut -f 1 -d " ")
80+
81+
# Only update if the action changes
82+
if [[ "$locked_version" != "$new_version" ]]; then
83+
echo "ℹ️ Locked version: $locked_version"
84+
echo "ℹ️ Current version: $new_version"
85+
echo "🆙 Updating existing workflow: $filename"
86+
echo "- 🆙 Updated [$filename](https://github.com/nextcloud/.github/commits/master/workflow-templates/$filename)" >> $GITHUB_ENV
87+
88+
cp "$workflow" "$target_file"
89+
90+
# Apply patch if one exists
91+
if [ -f "$target_file.patch" ]; then
92+
echo "🩹 Applying patch"
93+
cd ./target
94+
set +e
95+
patch -p1 < ".github/workflows/$filename.patch"
96+
patch_worked=$?
97+
set -e
98+
cd -
99+
if [[ "$patch_worked" == "0" ]]; then
100+
echo " - Patch applied" >> $GITHUB_ENV
101+
else
102+
echo " - [ ] ❌ Patch failed" >> $GITHUB_ENV
103+
draft_only=1
104+
fi
105+
fi
106+
107+
if [[ "$locked_version" != "" ]]; then
108+
sed -i "s/$locked_version $filename/$new_version $filename/" ./target/.github/actions-lock.txt
109+
else
110+
echo "$new_version $filename" >> ./target/.github/actions-lock.txt
111+
fi
112+
else
113+
echo "✅ Skipping $filename: already up to date"
114+
fi
115+
else
116+
echo "⏭️ Skipping $filename: does not exist in target repository"
117+
fi
118+
fi
119+
done
120+
echo 'EOF' >> $GITHUB_ENV
121+
echo "DRAFT_ONLY=${draft_only}" >> $GITHUB_ENV
122+
123+
- name: Create Pull Request
124+
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
125+
with:
126+
token: ${{ secrets.COMMAND_BOT_WORKFLOWS }}
127+
commit-message: 'ci(actions): Update workflow templates from organization template repository'
128+
committer: GitHub <noreply@github.com>
129+
author: nextcloud-command <nextcloud-command@users.noreply.github.com>
130+
path: target
131+
signoff: true
132+
branch: 'automated/noid/${{ matrix.branches }}-update-workflows'
133+
title: '[${{ matrix.branches }}] ci(actions): Update workflow templates from organization template repository'
134+
draft: ${{ env.DRAFT_ONLY == 1 }}
135+
add-paths: .github/workflows/*.yml,.github/actions-lock.txt
136+
body: |
137+
Automated update of all workflow templates from [nextcloud/.github](https://github.com/nextcloud/.github)
138+
${{ env.SUMMARY }}
139+
labels: |
140+
dependencies
141+
3. to review

‎workflow-catalog.json‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@
1111
"npm-build",
1212
"openapi",
1313
"psalm",
14-
"reuse"
14+
"reuse",
15+
"sync-workflow-templates"
1516
]
1617
}

0 commit comments

Comments
 (0)