-
Notifications
You must be signed in to change notification settings - Fork 0
93 lines (82 loc) · 3.12 KB
/
Copy pathci.yml
File metadata and controls
93 lines (82 loc) · 3.12 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
name: Node CI
on:
pull_request:
push:
branches:
- main
workflow_dispatch:
permissions:
contents: read
pull-requests: read
concurrency:
group: node-ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
test:
name: Node CI
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
steps:
- name: Checkout trusted dependency authorization helper
if: >-
github.event_name == 'pull_request' &&
github.event.pull_request.user.login == 'dependabot[bot]'
uses: actions/checkout@v7
with:
persist-credentials: false
ref: ${{ github.event.pull_request.base.sha }}
- name: Authorize Dependabot update before checking out its head
if: >-
github.event_name == 'pull_request' &&
github.event.pull_request.user.login == 'dependabot[bot]'
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_NUMBER: ${{ github.event.pull_request.number }}
REPOSITORY: ${{ github.repository }}
run: |
set -euo pipefail
changed_files="${RUNNER_TEMP}/dependabot-changed-files"
commits="${RUNNER_TEMP}/dependabot-commits.json"
ancestry_proofs="${RUNNER_TEMP}/dependabot-ancestry-proofs.json"
ancestry_proof_items="${RUNNER_TEMP}/dependabot-ancestry-proof-items.jsonl"
gh api --paginate \
"repos/${REPOSITORY}/pulls/${PR_NUMBER}/files?per_page=100" \
--jq '.[].filename' > "${changed_files}"
gh api --paginate --slurp \
"repos/${REPOSITORY}/pulls/${PR_NUMBER}/commits?per_page=100" \
> "${commits}"
: > "${ancestry_proof_items}"
while IFS= read -r second_parent; do
gh api "repos/${REPOSITORY}/compare/${second_parent}...${BASE_SHA}" |
jq -c --arg parent_sha "${second_parent}" --arg base_sha "${BASE_SHA}" \
'{parent_sha, base_sha, base_commit: .base_commit.sha, head_commit: .head_commit.sha, merge_base_commit: .merge_base_commit.sha, status, ahead_by, behind_by}' \
>> "${ancestry_proof_items}"
done < <(jq -r '.[].[] | select(.parents | length == 2) | .parents[1].sha' "${commits}")
jq -s . "${ancestry_proof_items}" > "${ancestry_proofs}"
node .github/scripts/dependabot-auto-merge.mjs \
"${GITHUB_EVENT_PATH}" "${changed_files}" "${commits}" "${ancestry_proofs}"
- name: Check out repository
uses: actions/checkout@v7
with:
persist-credentials: false
- name: Set up Go
uses: actions/setup-go@v7
with:
go-version-file: go.mod
cache: true
cache-dependency-path: go.sum
- name: Set up Node.js
uses: actions/setup-node@v7
with:
node-version: 24
cache: npm
cache-dependency-path: package-lock.json
- name: Install dependencies
run: npm ci
- name: Run lint
run: npm run lint
- name: Run tests
run: npm test