chore(codeapi): remediate SCA dependency findings (#3414) #10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Companion to the monorepo publish pipeline: snapshots arrive on the | |
| # sync/main branch (pushed via deploy key), and this workflow makes sure an | |
| # open pull request into main exists for them. Merging that PR is the | |
| # release step — main accepts no direct pushes. | |
| name: Open sync PR | |
| on: | |
| push: | |
| branches: ['sync/main'] | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| concurrency: | |
| group: open-sync-pr | |
| cancel-in-progress: false | |
| jobs: | |
| open-pr: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - name: Open PR from sync/main if none exists | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| OPEN=$(gh api -X GET "repos/${GITHUB_REPOSITORY}/pulls" \ | |
| -f state=open -f base=main -f head="${GITHUB_REPOSITORY_OWNER}:sync/main" \ | |
| -f per_page=1 --jq length) | |
| if [ "$OPEN" -gt 0 ]; then | |
| echo "Sync PR already open." | |
| exit 0 | |
| fi | |
| gh pr create \ | |
| --head sync/main --base main \ | |
| --title "$(git log -1 --format=%s)" \ | |
| --body "Automated snapshot sync from the internal monorepo. Merging this PR releases the changes to main. Commit trailers reference the source commits." |