From dc18eaa786e4249280a15b4101c42d2fa32de8a4 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Mon, 21 Sep 2026 22:55:16 -0300 Subject: [PATCH 1/3] fix: use organization app variable and targeted release fetch Signed-off-by: Vitor Mattos --- VERSION | 2 +- actions/release-post-merge/action.yml | 2 +- actions/release-prepare/action.yml | 2 +- docs/cross-repository-automation.md | 6 ++--- tests/test_prepare_release_template.py | 14 +++++++--- workflow-templates/prepare-release.yml | 26 +++++++++++++++---- .../sync-workflow-templates.yml | 4 +-- 7 files changed, 40 insertions(+), 16 deletions(-) diff --git a/VERSION b/VERSION index b616048..844f6a9 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -0.6.2 +0.6.3 diff --git a/actions/release-post-merge/action.yml b/actions/release-post-merge/action.yml index 1f31e68..0c030ae 100644 --- a/actions/release-post-merge/action.yml +++ b/actions/release-post-merge/action.yml @@ -58,7 +58,7 @@ runs: set -euo pipefail if [[ -z "${RELEASE_APP_ID}" ]]; then - echo "::error::GitHub App id is empty. Configure LIBRECODE_WORKFLOW_APP_ID as an Actions secret in the consumer repository or organization." + echo "::error::GitHub App id is empty. Configure LIBRECODE_WORKFLOW_APP_ID as an Actions variable in the consumer repository or organization." exit 1 fi if [[ ! "${RELEASE_APP_ID}" =~ ^[0-9]+$ ]]; then diff --git a/actions/release-prepare/action.yml b/actions/release-prepare/action.yml index b38b9a8..8c37fea 100644 --- a/actions/release-prepare/action.yml +++ b/actions/release-prepare/action.yml @@ -82,7 +82,7 @@ runs: set -euo pipefail if [[ -z "${RELEASE_APP_ID}" ]]; then - echo "::error::GitHub App id is empty. Configure LIBRECODE_WORKFLOW_APP_ID as an Actions secret in the consumer repository or organization." + echo "::error::GitHub App id is empty. Configure LIBRECODE_WORKFLOW_APP_ID as an Actions variable in the consumer repository or organization." exit 1 fi if [[ ! "${RELEASE_APP_ID}" =~ ^[0-9]+$ ]]; then diff --git a/docs/cross-repository-automation.md b/docs/cross-repository-automation.md index e9a75e2..b27637f 100644 --- a/docs/cross-repository-automation.md +++ b/docs/cross-repository-automation.md @@ -40,15 +40,15 @@ permissions are required. `LibreCodeCoop/github-workflows` stores: -- Actions secret `LIBRECODE_WORKFLOW_APP_ID`; +- Actions variable `LIBRECODE_WORKFLOW_APP_ID`; - Actions secret `LIBRECODE_WORKFLOW_APP_PRIVATE_KEY`. Consumer repositories that execute write-capable release orchestration also need -both secrets available in their own Actions context, either directly at +those values available in their own Actions context, either directly at repository level or inherited from an organization configuration that includes the repository: -- Actions secret `LIBRECODE_WORKFLOW_APP_ID`; +- Actions variable `LIBRECODE_WORKFLOW_APP_ID`; - Actions secret `LIBRECODE_WORKFLOW_APP_PRIVATE_KEY`. The GitHub App installation must also include the consumer repository. A diff --git a/tests/test_prepare_release_template.py b/tests/test_prepare_release_template.py index 9538dbe..9a1f2ba 100644 --- a/tests/test_prepare_release_template.py +++ b/tests/test_prepare_release_template.py @@ -58,12 +58,20 @@ def test_template_delegates_all_release_stages_to_versioned_actions(self) -> Non content, ) - def test_release_mutation_credentials_use_actions_secrets(self) -> None: + def test_release_mutation_credentials_use_org_variable_and_secret(self) -> None: content = TEMPLATE.read_text(encoding="utf-8") - self.assertEqual(2, content.count("secrets.LIBRECODE_WORKFLOW_APP_ID")) + self.assertEqual(2, content.count("vars.LIBRECODE_WORKFLOW_APP_ID")) self.assertEqual(2, content.count("secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY")) - self.assertNotIn("vars.LIBRECODE_WORKFLOW_APP_ID", content) + self.assertNotIn("secrets.LIBRECODE_WORKFLOW_APP_ID", content) + + def test_release_checkout_fetches_only_selected_branch_history_and_tags(self) -> None: + content = TEMPLATE.read_text(encoding="utf-8") + + self.assertIn("fetch-depth: 1", content) + self.assertIn('refs/heads/${RELEASE_BRANCH}:refs/remotes/origin/${RELEASE_BRANCH}', content) + self.assertIn('refs/tags/*:refs/tags/*', content) + self.assertNotIn("fetch-depth: 0", content) def test_template_keeps_permissions_stage_scoped(self) -> None: content = TEMPLATE.read_text(encoding="utf-8") diff --git a/workflow-templates/prepare-release.yml b/workflow-templates/prepare-release.yml index e2aa36a..7b88b74 100644 --- a/workflow-templates/prepare-release.yml +++ b/workflow-templates/prepare-release.yml @@ -76,9 +76,17 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - fetch-depth: 0 + fetch-depth: 1 ref: ${{ inputs.ref != '' && inputs.ref || inputs.branch }} + - name: Fetch selected release history + shell: bash + env: + RELEASE_BRANCH: ${{ inputs.branch }} + run: | + set -euo pipefail + git fetch --unshallow --prune origin "+refs/heads/${RELEASE_BRANCH}:refs/remotes/origin/${RELEASE_BRANCH}" "+refs/tags/*:refs/tags/*" + - name: Prepare release uses: LibreCodeCoop/github-workflows/actions/release-prepare@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2 with: @@ -93,7 +101,7 @@ jobs: config-path: .nextcloud-release.yml actor: ${{ github.actor }} github-token: ${{ secrets.GITHUB_TOKEN }} - app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} + app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} app-private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} post_merge: @@ -114,9 +122,17 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - fetch-depth: 0 + fetch-depth: 1 ref: ${{ github.event.pull_request.base.ref }} + - name: Fetch merged release history + shell: bash + env: + RELEASE_BRANCH: ${{ github.event.pull_request.base.ref }} + run: | + set -euo pipefail + git fetch --unshallow --prune origin "+refs/heads/${RELEASE_BRANCH}:refs/remotes/origin/${RELEASE_BRANCH}" "+refs/tags/*:refs/tags/*" + - name: Finalize merged release uses: LibreCodeCoop/github-workflows/actions/release-post-merge@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2 with: @@ -125,7 +141,7 @@ jobs: config-path: .nextcloud-release.yml prepare-workflow-path: .github/workflows/prepare-release.yml github-token: ${{ secrets.GITHUB_TOKEN }} - app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} + app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} app-private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} verify_publication: @@ -141,7 +157,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - fetch-depth: 0 + fetch-depth: 1 ref: ${{ github.event.release.tag_name }} - name: Verify publication diff --git a/workflow-templates/sync-workflow-templates.yml b/workflow-templates/sync-workflow-templates.yml index 8302ce5..a0e59f2 100644 --- a/workflow-templates/sync-workflow-templates.yml +++ b/workflow-templates/sync-workflow-templates.yml @@ -46,7 +46,7 @@ jobs: shell: bash env: AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }} - LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} + LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} LIBRECODE_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} CONSUMER_APP_ID: ${{ vars.WORKFLOW_SYNC_APP_ID }} CONSUMER_APP_PRIVATE_KEY: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }} @@ -86,7 +86,7 @@ jobs: id: librecode-app-token uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 with: - app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} + app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} owner: ${{ github.repository_owner }} repositories: ${{ github.event.repository.name }} From 7559e933c7978d3e54f41d9636bd5e6ab7994d82 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Mon, 21 Sep 2026 22:56:03 -0300 Subject: [PATCH 2/3] test: align sync auth contract with app id variable Signed-off-by: Vitor Mattos --- tests/test_portable_workflow_sync_auth.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/tests/test_portable_workflow_sync_auth.py b/tests/test_portable_workflow_sync_auth.py index 2b34760..b7feb77 100644 --- a/tests/test_portable_workflow_sync_auth.py +++ b/tests/test_portable_workflow_sync_auth.py @@ -29,12 +29,12 @@ def test_external_modes_do_not_require_librecode_credentials(self) -> None: self.assertIn('github-app) token="${CONSUMER_APP_TOKEN}"', content) self.assertIn('token) token="${CONSUMER_TOKEN}"', content) - def test_librecode_app_credentials_use_actions_secrets(self) -> None: + def test_librecode_app_credentials_use_actions_variable_and_secret(self) -> None: content = TEMPLATE.read_text(encoding="utf-8") - self.assertIn("LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}", content) - self.assertIn("app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}", content) - self.assertNotIn("vars.LIBRECODE_WORKFLOW_APP_ID", content) + self.assertIn("LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}", content) + self.assertIn("app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}", content) + self.assertNotIn("secrets.LIBRECODE_WORKFLOW_APP_ID", content) def test_generated_pull_request_uses_selected_token(self) -> None: content = TEMPLATE.read_text(encoding="utf-8") From 45a427f957e29b35201731ee8647a1e209045052 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Mon, 21 Sep 2026 22:56:42 -0300 Subject: [PATCH 3/3] fix: keep sync workflow auth generated from patch Signed-off-by: Vitor Mattos --- patches/nextcloud/sync-workflow-templates.yml.patch | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/patches/nextcloud/sync-workflow-templates.yml.patch b/patches/nextcloud/sync-workflow-templates.yml.patch index 64ff318..076776a 100644 --- a/patches/nextcloud/sync-workflow-templates.yml.patch +++ b/patches/nextcloud/sync-workflow-templates.yml.patch @@ -38,7 +38,7 @@ + shell: bash + env: + AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }} -+ LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} ++ LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + LIBRECODE_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} + CONSUMER_APP_ID: ${{ vars.WORKFLOW_SYNC_APP_ID }} + CONSUMER_APP_PRIVATE_KEY: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }} @@ -78,7 +78,7 @@ + id: librecode-app-token + uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + with: -+ app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }} ++ app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} + owner: ${{ github.repository_owner }} + repositories: ${{ github.event.repository.name }}