Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
0.6.2
0.6.3
2 changes: 1 addition & 1 deletion actions/release-post-merge/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ runs:
set -euo pipefail

if [[ -z "${RELEASE_APP_ID}" ]]; then
echo "::error::GitHub App id is empty. Configure LIBRECODE_WORKFLOW_APP_ID as an Actions secret in the consumer repository or organization."
echo "::error::GitHub App id is empty. Configure LIBRECODE_WORKFLOW_APP_ID as an Actions variable in the consumer repository or organization."
exit 1
fi
if [[ ! "${RELEASE_APP_ID}" =~ ^[0-9]+$ ]]; then
Expand Down
2 changes: 1 addition & 1 deletion actions/release-prepare/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ runs:
set -euo pipefail

if [[ -z "${RELEASE_APP_ID}" ]]; then
echo "::error::GitHub App id is empty. Configure LIBRECODE_WORKFLOW_APP_ID as an Actions secret in the consumer repository or organization."
echo "::error::GitHub App id is empty. Configure LIBRECODE_WORKFLOW_APP_ID as an Actions variable in the consumer repository or organization."
exit 1
fi
if [[ ! "${RELEASE_APP_ID}" =~ ^[0-9]+$ ]]; then
Expand Down
6 changes: 3 additions & 3 deletions docs/cross-repository-automation.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,15 +40,15 @@ permissions are required.

`LibreCodeCoop/github-workflows` stores:

- Actions secret `LIBRECODE_WORKFLOW_APP_ID`;
- Actions variable `LIBRECODE_WORKFLOW_APP_ID`;
- Actions secret `LIBRECODE_WORKFLOW_APP_PRIVATE_KEY`.

Consumer repositories that execute write-capable release orchestration also need
both secrets available in their own Actions context, either directly at
those values available in their own Actions context, either directly at
repository level or inherited from an organization configuration that includes
the repository:

- Actions secret `LIBRECODE_WORKFLOW_APP_ID`;
- Actions variable `LIBRECODE_WORKFLOW_APP_ID`;
- Actions secret `LIBRECODE_WORKFLOW_APP_PRIVATE_KEY`.

The GitHub App installation must also include the consumer repository. A
Expand Down
4 changes: 2 additions & 2 deletions patches/nextcloud/sync-workflow-templates.yml.patch
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@
+ shell: bash
+ env:
+ AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }}
+ LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
+ LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
+ LIBRECODE_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}
+ CONSUMER_APP_ID: ${{ vars.WORKFLOW_SYNC_APP_ID }}
+ CONSUMER_APP_PRIVATE_KEY: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }}
Expand Down Expand Up @@ -78,7 +78,7 @@
+ id: librecode-app-token
+ uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4
+ with:
+ app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
+ app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
+ private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}
+ owner: ${{ github.repository_owner }}
+ repositories: ${{ github.event.repository.name }}
Expand Down
8 changes: 4 additions & 4 deletions tests/test_portable_workflow_sync_auth.py
Original file line number Diff line number Diff line change
Expand Up @@ -29,12 +29,12 @@ def test_external_modes_do_not_require_librecode_credentials(self) -> None:
self.assertIn('github-app) token="${CONSUMER_APP_TOKEN}"', content)
self.assertIn('token) token="${CONSUMER_TOKEN}"', content)

def test_librecode_app_credentials_use_actions_secrets(self) -> None:
def test_librecode_app_credentials_use_actions_variable_and_secret(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")

self.assertIn("LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}", content)
self.assertIn("app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}", content)
self.assertNotIn("vars.LIBRECODE_WORKFLOW_APP_ID", content)
self.assertIn("LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}", content)
self.assertIn("app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}", content)
self.assertNotIn("secrets.LIBRECODE_WORKFLOW_APP_ID", content)

def test_generated_pull_request_uses_selected_token(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")
Expand Down
14 changes: 11 additions & 3 deletions tests/test_prepare_release_template.py
Original file line number Diff line number Diff line change
Expand Up @@ -58,12 +58,20 @@ def test_template_delegates_all_release_stages_to_versioned_actions(self) -> Non
content,
)

def test_release_mutation_credentials_use_actions_secrets(self) -> None:
def test_release_mutation_credentials_use_org_variable_and_secret(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")

self.assertEqual(2, content.count("secrets.LIBRECODE_WORKFLOW_APP_ID"))
self.assertEqual(2, content.count("vars.LIBRECODE_WORKFLOW_APP_ID"))
self.assertEqual(2, content.count("secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY"))
self.assertNotIn("vars.LIBRECODE_WORKFLOW_APP_ID", content)
self.assertNotIn("secrets.LIBRECODE_WORKFLOW_APP_ID", content)

def test_release_checkout_fetches_only_selected_branch_history_and_tags(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")

self.assertIn("fetch-depth: 1", content)
self.assertIn('refs/heads/${RELEASE_BRANCH}:refs/remotes/origin/${RELEASE_BRANCH}', content)
self.assertIn('refs/tags/*:refs/tags/*', content)
self.assertNotIn("fetch-depth: 0", content)

def test_template_keeps_permissions_stage_scoped(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")
Expand Down
26 changes: 21 additions & 5 deletions workflow-templates/prepare-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,9 +76,17 @@ jobs:
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
fetch-depth: 0
fetch-depth: 1
ref: ${{ inputs.ref != '' && inputs.ref || inputs.branch }}

- name: Fetch selected release history
shell: bash
env:
RELEASE_BRANCH: ${{ inputs.branch }}
run: |
set -euo pipefail
git fetch --unshallow --prune origin "+refs/heads/${RELEASE_BRANCH}:refs/remotes/origin/${RELEASE_BRANCH}" "+refs/tags/*:refs/tags/*"

- name: Prepare release
uses: LibreCodeCoop/github-workflows/actions/release-prepare@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2
with:
Expand All @@ -93,7 +101,7 @@ jobs:
config-path: .nextcloud-release.yml
actor: ${{ github.actor }}
github-token: ${{ secrets.GITHUB_TOKEN }}
app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
app-private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}

post_merge:
Expand All @@ -114,9 +122,17 @@ jobs:
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
fetch-depth: 0
fetch-depth: 1
ref: ${{ github.event.pull_request.base.ref }}

- name: Fetch merged release history
shell: bash
env:
RELEASE_BRANCH: ${{ github.event.pull_request.base.ref }}
run: |
set -euo pipefail
git fetch --unshallow --prune origin "+refs/heads/${RELEASE_BRANCH}:refs/remotes/origin/${RELEASE_BRANCH}" "+refs/tags/*:refs/tags/*"

- name: Finalize merged release
uses: LibreCodeCoop/github-workflows/actions/release-post-merge@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2
with:
Expand All @@ -125,7 +141,7 @@ jobs:
config-path: .nextcloud-release.yml
prepare-workflow-path: .github/workflows/prepare-release.yml
github-token: ${{ secrets.GITHUB_TOKEN }}
app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
app-private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}

verify_publication:
Expand All @@ -141,7 +157,7 @@ jobs:
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
fetch-depth: 0
fetch-depth: 1
ref: ${{ github.event.release.tag_name }}

- name: Verify publication
Expand Down
4 changes: 2 additions & 2 deletions workflow-templates/sync-workflow-templates.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ jobs:
shell: bash
env:
AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }}
LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
LIBRECODE_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}
CONSUMER_APP_ID: ${{ vars.WORKFLOW_SYNC_APP_ID }}
CONSUMER_APP_PRIVATE_KEY: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }}
Expand Down Expand Up @@ -86,7 +86,7 @@ jobs:
id: librecode-app-token
uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4
with:
app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}
owner: ${{ github.repository_owner }}
repositories: ${{ github.event.repository.name }}
Expand Down
Loading