From ec32a210f78a798f85a007db7e22b778fec05d40 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 19:54:49 -0300 Subject: [PATCH 1/4] fix: make workflow sync owner repository-generic Signed-off-by: Vitor Mattos --- patches/nextcloud/sync-workflow-templates.yml.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/patches/nextcloud/sync-workflow-templates.yml.patch b/patches/nextcloud/sync-workflow-templates.yml.patch index 3bb152a..18fa29a 100644 --- a/patches/nextcloud/sync-workflow-templates.yml.patch +++ b/patches/nextcloud/sync-workflow-templates.yml.patch @@ -28,7 +28,7 @@ + with: + app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} -+ owner: LibreCodeCoop ++ owner: ${{ github.repository_owner }} + repositories: ${{ github.event.repository.name }} + permission-contents: write + permission-pull-requests: write From 07f5d150a0b6a0556724d1d70b8d64f52abf110d Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 19:54:51 -0300 Subject: [PATCH 2/4] fix: remove catalog-orphaned workflow lock entries Signed-off-by: Vitor Mattos --- actions/sync-workflows/sync.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/actions/sync-workflows/sync.py b/actions/sync-workflows/sync.py index 1db33a9..e228edb 100644 --- a/actions/sync-workflows/sync.py +++ b/actions/sync-workflows/sync.py @@ -132,6 +132,10 @@ def sync( source_by_name = {path.name: path for path in workflow_files(source)} + stale_entries = sorted(set(entries) - set(source_by_name)) + for name in stale_entries: + del entries[name] + for name in sorted(entries): if name in source_by_name: target_file = target / ".github/workflows" / name @@ -206,7 +210,7 @@ def sync( if not patch_ok: failed.append(name) - lock_changed = bool(updated or adopted) + lock_changed = bool(updated or adopted or stale_entries) if lock_changed: write_lock(lock_path, entries) @@ -221,6 +225,7 @@ def sync( "failed": failed, "diverged": diverged, "details": details, + "removed_from_lock": stale_entries, } From 324c9b29fb4c6a7c3ff031604d9a840f6cee1dc0 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 19:54:54 -0300 Subject: [PATCH 3/4] test: cover stale workflow lock cleanup Signed-off-by: Vitor Mattos --- tests/test_sync_workflows_action.py | 37 +++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) diff --git a/tests/test_sync_workflows_action.py b/tests/test_sync_workflows_action.py index 7724986..9604072 100644 --- a/tests/test_sync_workflows_action.py +++ b/tests/test_sync_workflows_action.py @@ -196,6 +196,43 @@ def test_broken_patch_sets_draft_signal_and_keeps_catalog_lock(self) -> None: sync_module.md5(source_file), ) + def test_removes_lock_entries_missing_from_catalog(self) -> None: + temporary, source, target = self.fixture() + with temporary: + current = source / "lint.yml" + current.write_text("name: Current\n", encoding="utf-8") + (target / ".github/workflows/lint.yml").write_text( + "name: Current\n", encoding="utf-8" + ) + stale = target / ".github/workflows/old.yml" + stale.write_text("name: Local old workflow\n", encoding="utf-8") + + sync_module.write_lock( + target / ".github/actions-lock.txt", + { + "lint.yml": sync_module.md5(current), + "old.yml": hashlib.md5( + b"name: Old catalog workflow\n", + usedforsecurity=False, + ).hexdigest(), + }, + ) + + report = sync_module.sync( + source, target, target / ".github/actions-lock.txt" + ) + + self.assertTrue(report["changed"]) + self.assertEqual(report["removed_from_lock"], ["old.yml"]) + self.assertEqual( + sync_module.parse_lock(target / ".github/actions-lock.txt"), + {"lint.yml": sync_module.md5(current)}, + ) + self.assertEqual( + stale.read_text(encoding="utf-8"), + "name: Local old workflow\n", + ) + def test_writes_single_line_github_output(self) -> None: with tempfile.TemporaryDirectory() as directory: output = Path(directory) / "output" From 4ba2ee360336e37f864d64ae6c705a58944e9927 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 19:55:39 -0300 Subject: [PATCH 4/4] build: regenerate workflow sync template Signed-off-by: Vitor Mattos --- workflow-templates/sync-workflow-templates.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/workflow-templates/sync-workflow-templates.yml b/workflow-templates/sync-workflow-templates.yml index a0eeda8..28cf315 100644 --- a/workflow-templates/sync-workflow-templates.yml +++ b/workflow-templates/sync-workflow-templates.yml @@ -45,7 +45,7 @@ jobs: with: app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} - owner: LibreCodeCoop + owner: ${{ github.repository_owner }} repositories: ${{ github.event.repository.name }} permission-contents: write permission-pull-requests: write