diff --git a/plugin-template b/plugin-template index 67feeb9e..cc8fc11c 100755 --- a/plugin-template +++ b/plugin-template @@ -185,6 +185,8 @@ DEPRECATED_FILES = { ".github/workflows/scripts/publish_client_gem.sh", ".github/workflows/scripts/publish_client_pypi.sh", ".github/workflows/scripts/publish_plugin_pypi.sh", + ".github/workflows/scripts/push_branch_and_tag_to_github.sh", + ".github/workflows/scripts/secrets.py", ".travis", ".travis.yml", "dev_requirements.txt", diff --git a/scripts/update_ci.sh b/scripts/update_ci.sh index c011a075..6b06b1d9 100755 --- a/scripts/update_ci.sh +++ b/scripts/update_ci.sh @@ -18,8 +18,14 @@ then "template_config.yml" fi -PLUGIN_NAME="$(python ../plugin_template/scripts/get_template_config_value.py plugin_name)" -CI_UPDATE_DOCS="$(python ../plugin_template/scripts/get_template_config_value.py ci_update_docs)" +if [[ $(git status --porcelain) ]] +then + echo "Working directory not clean. Aborting." + exit 1 +fi + +PLUGIN_NAME="$(uv run --script ../plugin_template/scripts/get_template_config_value.py plugin_name)" +CI_UPDATE_DOCS="$(uv run --script ../plugin_template/scripts/get_template_config_value.py ci_update_docs)" if [[ "${CI_UPDATE_DOCS}" == "True" ]]; then DOCS=("--docs") @@ -27,10 +33,7 @@ else DOCS=() fi -pushd ../plugin_template - pip install -r requirements.txt - ./plugin-template --github "${DOCS[@]}" "${PLUGIN_NAME}" -popd +uv run --script ../plugin_template/plugin-template --github "${DOCS[@]}" if [[ $(git status --porcelain) ]]; then git add -A @@ -41,7 +44,7 @@ fi # Check that pulpcore lowerbounds is set to a supported branch if [[ "${PLUGIN_NAME}" != "pulpcore" ]]; then - python ../plugin_template/scripts/update_core_lowerbound.py + uv run --script ../plugin_template/scripts/update_core_lowerbound.py if [[ $(git status --porcelain) ]]; then git add -A git commit -m "Bump pulpcore lowerbounds to supported branch" diff --git a/templates/github/.github/workflows/create-branch.yml.j2 b/templates/github/.github/workflows/create-branch.yml.j2 index 670a4048..529f13c4 100644 --- a/templates/github/.github/workflows/create-branch.yml.j2 +++ b/templates/github/.github/workflows/create-branch.yml.j2 @@ -2,7 +2,6 @@ {% from 'macros.j2' import checkout, setup_python, - set_secrets, install_python_deps with context %} --- @@ -23,18 +22,17 @@ jobs: permissions: contents: "write" + pull-requests: "write" steps: {{ checkout(depth=0, path=plugin_name) | indent(6) }} {{ checkout(repository="pulp/plugin_template", path="plugin_template") | indent(6) }} - {{ setup_python() | indent(6) }} + {{ setup_python(pyversion="3.12") | indent(6) }} {{ install_python_deps(["bump-my-version", "packaging", "-r", "plugin_template/requirements.txt"]) | indent(6) }} - {{ set_secrets(path=plugin_name) | indent(6) }} - - name: "Determine new branch name" working-directory: "{{ plugin_name }}" run: | @@ -73,9 +71,6 @@ jobs: uses: "peter-evans/create-pull-request@v8" with: path: "{{ plugin_name }}" - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} committer: "{{release_user}} <{{ release_email }}>" author: "{{release_user}} <{{ release_email }}>" branch: "minor-version-bump" diff --git a/templates/github/.github/workflows/nightly.yml.j2 b/templates/github/.github/workflows/nightly.yml.j2 index abbe1c1d..dbeccbeb 100644 --- a/templates/github/.github/workflows/nightly.yml.j2 +++ b/templates/github/.github/workflows/nightly.yml.j2 @@ -2,15 +2,11 @@ {% from 'macros.j2' import checkout, configure_git, - display_logs, - install_python_deps, matrix_env, - run_script, - setup_env, setup_python, with context %} --- -name: "{{ plugin_app_label | camel }} Nightly CI" +name: "Nightly CI" on: schedule: # * is a special character in YAML so you have to quote this string @@ -49,21 +45,19 @@ jobs: {{ setup_python(pyversion="3.13") | indent(6) }} - {{ install_python_deps(["gitpython", "packaging", "toml"]) | indent(6) }} - {{ configure_git() | indent(6) }} - name: "Collect changes from all branches" run: | - python .ci/scripts/collect_changes.py + uv run --script .ci/scripts/collect_changes.py - name: "Create Pull Request" uses: "peter-evans/create-pull-request@v8" id: "create_pr_changelog" + permissions: + contents: "write" + pull-requests: "write" with: - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} title: "Update Changelog" body: "" branch: "changelog/update" @@ -71,6 +65,9 @@ jobs: path: "{{ plugin_name }}" - name: "Mark PR automerge" working-directory: "{{ plugin_name }}" + permissions: + contents: "write" + pull-requests: "write" run: | {%- raw %} gh pr merge --rebase --auto "${{ steps.create_pr_changelog.outputs.pull-request-number }}" @@ -78,7 +75,7 @@ jobs: if: "steps.create_pr_changelog.outputs.pull-request-number" env: {%- raw %} - GH_TOKEN: "${{ secrets.RELEASE_TOKEN }}" + GH_TOKEN: "${{ secrets.GITHUB_TOKEN }}" {%- endraw %} continue-on-error: true ... diff --git a/templates/github/.github/workflows/publish.yml.j2 b/templates/github/.github/workflows/publish.yml.j2 index 8c381ef0..c4251ea0 100644 --- a/templates/github/.github/workflows/publish.yml.j2 +++ b/templates/github/.github/workflows/publish.yml.j2 @@ -1,17 +1,12 @@ {% include 'header.j2' %} {% from 'macros.j2' import - set_env_vars, checkout, setup_python, setup_ruby, - display_logs, run_script, - set_secrets, - install_python_deps, - configure_git, with context %} --- -name: "{{ plugin_app_label | camel }} Publish Release" +name: "Publish Release" on: push: tags: @@ -149,17 +144,13 @@ jobs: {{ setup_python(pyversion="3.11") | indent(6) }} - - name: "Install towncrier" - run: | - uv pip install towncrier - - name: "Get release notes" id: "get_release_notes" shell: "bash" run: | # The last commit before the release commit contains the release CHANGES fragments git checkout "${TAG_NAME}~" - NOTES=$(towncrier build --draft --version $TAG_NAME | .ci/scripts/clean_gh_release_notes.py {{ plugin_name }} $TAG_NAME) + NOTES=$(uvx towncrier build --draft --version $TAG_NAME | uv run --script .ci/scripts/clean_gh_release_notes.py {{ plugin_name }} $TAG_NAME) echo "body<> $GITHUB_OUTPUT echo "$NOTES" >> $GITHUB_OUTPUT echo "EOF" >> $GITHUB_OUTPUT diff --git a/templates/github/.github/workflows/release.yml.j2 b/templates/github/.github/workflows/release.yml.j2 index 92374ef2..b1474742 100644 --- a/templates/github/.github/workflows/release.yml.j2 +++ b/templates/github/.github/workflows/release.yml.j2 @@ -1,17 +1,13 @@ {% include 'header.j2' %} {% from 'macros.j2' import - set_env_vars, checkout, setup_python, - setup_ruby, - display_logs, run_script, - set_secrets, install_python_deps, configure_git, with context %} --- -name: {{ plugin_app_label | camel }} Release Pipeline +name: "Tag Release" on: workflow_dispatch: @@ -29,16 +25,15 @@ jobs: strategy: fail-fast: false - steps: - {{ checkout(depth=0, path=plugin_name, use_release_token=true) | indent(6) }} + permissions: + contents: "write" - {{ setup_python() | indent(6) }} + steps: + {{ checkout(depth=0, path=plugin_name) | indent(6) }} - {{ install_python_deps(["bump-my-version", "towncrier"]) | indent(6) }} + {{ setup_python(pyversion="3.12") | indent(6) }} {{ configure_git() | indent(6) }} - {{ set_secrets() | indent(6) }} - {{ run_script(name="Tag the release", file="release.sh") | indent(6) }} ... diff --git a/templates/github/.github/workflows/sanity.yml.j2 b/templates/github/.github/workflows/sanity.yml.j2 index cf199eeb..7a5ddada 100644 --- a/templates/github/.github/workflows/sanity.yml.j2 +++ b/templates/github/.github/workflows/sanity.yml.j2 @@ -28,23 +28,21 @@ jobs: {{ setup_python(pyversion="3.12") | indent(6) }} - {{ install_python_deps(["-r", "lint_requirements.txt"]) | indent(6) }} - - name: "Verify bump version config" run: | - bump-my-version bump --dry-run release - bump-my-version show-bump + uvx bump-my-version bump --dry-run release + uvx bump-my-version show-bump {%- if check_manifest %} - name: "Check for any files unintentionally left out of MANIFEST.in" run: | - check-manifest + uvx check-manifest {%- endif %} {%- if lint_requirements %} - name: "Verify requirements files" run: | - python .ci/scripts/check_requirements.py + uv run --script .ci/scripts/check_requirements.py {%- endif %} {%- if check_stray_pulpcore_imports %} diff --git a/templates/github/.github/workflows/scripts/release.sh b/templates/github/.github/workflows/scripts/release.sh index 40bbcb19..9b04fcb7 100755 --- a/templates/github/.github/workflows/scripts/release.sh +++ b/templates/github/.github/workflows/scripts/release.sh @@ -11,7 +11,7 @@ then fi # The tail is a necessary workaround to remove the warning from the output. -NEW_VERSION="$(bump-my-version show new_version --increment release | tail -n -1)" +NEW_VERSION="$(uvx bump-my-version show new_version --increment release | tail -n -1)" echo "Release ${NEW_VERSION}" if ! [[ "${NEW_VERSION}" == "${BRANCH}"* ]] @@ -20,9 +20,9 @@ then exit 1 fi -towncrier build --yes --version "${NEW_VERSION}" -bump-my-version bump release --commit --message "Release {new_version}" --tag --tag-name "{new_version}" --tag-message "Release {new_version}" --allow-dirty -bump-my-version bump patch --commit +uvx towncrier build --yes --version "${NEW_VERSION}" +uvx bump-my-version bump release --commit --message "Release {new_version}" --tag --tag-name "{new_version}" --tag-message "Release {new_version}" --allow-dirty +uvx bump-my-version bump patch --commit # Git push is not atomic by default! git push --atomic origin "${BRANCH}" "${NEW_VERSION}" diff --git a/templates/github/.github/workflows/scripts/secrets.py.j2 b/templates/github/.github/workflows/scripts/secrets.py.j2 deleted file mode 100644 index af5ef74c..00000000 --- a/templates/github/.github/workflows/scripts/secrets.py.j2 +++ /dev/null @@ -1,14 +0,0 @@ -import json -import os -import sys - -secrets = json.loads(sys.argv[1]) -for key, value in secrets.items(): - print(f"Setting {key} ...") - lines = len(value.split("\n")) - if lines > 1: - os.system(f"/bin/bash -c \"echo '{key}<> $GITHUB_ENV\"") - os.system(f"/bin/bash -c \"echo '{value}' >> $GITHUB_ENV\"") - os.system("/bin/bash -c \"echo 'EOF' >> $GITHUB_ENV\"") - else: - os.system(f"/bin/bash -c \"echo '{key}={value}' >> $GITHUB_ENV\"") diff --git a/templates/github/.github/workflows/scripts/update_backport_labels.py.j2 b/templates/github/.github/workflows/scripts/update_backport_labels.py.j2 index 6bb3e528..27e9ae66 100644 --- a/templates/github/.github/workflows/scripts/update_backport_labels.py.j2 +++ b/templates/github/.github/workflows/scripts/update_backport_labels.py.j2 @@ -10,11 +10,12 @@ # This script is running with elevated privileges from the main branch against pull requests. -import requests -import yaml import random import os +import requests +import yaml + def random_color(): """Generates a random 24-bit number in hex""" diff --git a/templates/github/.github/workflows/update-labels.yml.j2 b/templates/github/.github/workflows/update-labels.yml.j2 index 91274467..0e5aad32 100644 --- a/templates/github/.github/workflows/update-labels.yml.j2 +++ b/templates/github/.github/workflows/update-labels.yml.j2 @@ -1,12 +1,10 @@ {% include 'header.j2' %} {% from 'macros.j2' import setup_python, - configure_git, - install_python_deps, with context %} --- -name: "{{ plugin_app_label | camel }} Update Labels" +name: "Update Labels" on: push: branches: @@ -22,13 +20,14 @@ jobs: runs-on: "ubuntu-latest" steps: {{ setup_python(pyversion="3.12") | indent(6) }} - {{ configure_git() | indent(6) }} - uses: "actions/checkout@v6" - name: "Update labels" + permissions: + issues: "write" run: | uv run --script .github/workflows/scripts/update_backport_labels.py env: {%- raw %} - GITHUB_TOKEN: "${{ secrets.RELEASE_TOKEN }}" + GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}" {%- endraw %} ... diff --git a/templates/github/.github/workflows/update_ci.yml.j2 b/templates/github/.github/workflows/update_ci.yml.j2 index a8e3c2b1..e6821e22 100644 --- a/templates/github/.github/workflows/update_ci.yml.j2 +++ b/templates/github/.github/workflows/update_ci.yml.j2 @@ -2,7 +2,6 @@ {% from 'macros.j2' import checkout, setup_python, - install_python_deps, configure_git, with context %} @@ -30,9 +29,7 @@ jobs: steps: {{ checkout(repository="pulp/plugin_template", path="plugin_template", depth=0) | indent(6) }} %# "depth=0" is needed to run "git describe". - {{ setup_python() | indent(6) }} - - {{ install_python_deps(["gitpython", "packaging", "-r", "plugin_template/requirements.txt"]) | indent(6) }} + {{ setup_python(pyversion="3.12") | indent(6) }} {{ configure_git() | indent(6) }} @@ -48,10 +45,10 @@ jobs: - name: "Create Pull Request for CI files" uses: "peter-evans/create-pull-request@v8" id: "create_pr_{{ branch_slug }}" + permissions: + contents: "write" + pull-requests: "write" with: - {%- raw %} - token: "${{ secrets.RELEASE_TOKEN }}" - {%- endraw %} path: "{{ plugin_name }}" committer: "{{ release_user }} <{{ release_email }}>" author: "{{ release_user }} <{{ release_email }}>" @@ -61,12 +58,15 @@ jobs: delete-branch: true - name: "Mark PR automerge" working-directory: "{{ plugin_name }}" + permissions: + contents: "write" + pull-requests: "write" run: | gh pr merge --rebase --auto "{{ '${{ steps.create_pr_' + branch_slug + '.outputs.pull-request-number }}' }}" if: "steps.create_pr_{{ branch_slug }}.outputs.pull-request-number" env: {%- raw %} - GH_TOKEN: "${{ secrets.RELEASE_TOKEN }}" + GH_TOKEN: "${{ secrets.GITHUB_TOKEN }}" {%- endraw %} continue-on-error: true {%- endfor %} diff --git a/templates/include/macros.j2 b/templates/include/macros.j2 index 3b8c1367..0e6c4861 100644 --- a/templates/include/macros.j2 +++ b/templates/include/macros.j2 @@ -14,7 +14,7 @@ GITHUB_CONTEXT: "{{ '${{ github.event.pull_request.commits_url }}' }}" {%- endmacro -%} -{%- macro checkout(depth=1, repository=None, path=None, ref=None, use_release_token=false) -%} +{%- macro checkout(depth=1, repository=None, path=None, ref=None) -%} - uses: "actions/checkout@v6" with: fetch-depth: {{ depth }} @@ -27,9 +27,6 @@ GITHUB_CONTEXT: "{{ '${{ github.event.pull_request.commits_url }}' }}" {%- if ref %} ref: "{{ ref }}" {%- endif %} - {%- if use_release_token %} - token: {{ "${{ secrets.RELEASE_TOKEN }}" }} - {%- endif %} {%- endmacro -%} @@ -118,21 +115,6 @@ GITHUB_CONTEXT: "{{ '${{ github.event.pull_request.commits_url }}' }}" {%- endmacro -%} -{%- macro set_secrets(condition=None, path=None) -%} -- name: "Setting secrets" - {%- if path %} - working-directory: "{{ path }}" - {%- endif %} - {%- if condition %} - if: {{ condition }} - {%- endif %} - run: | - python3 .github/workflows/scripts/secrets.py "$SECRETS_CONTEXT" - env: - SECRETS_CONTEXT: "{{ '${{ toJson(secrets) }}' }}" -{%- endmacro -%} - - {%- macro configure_git() -%} - name: "Configure Git with {{ release_user }} name and email" run: |