Skip to content

chore: sync public mirror from internal (#1056) #178

chore: sync public mirror from internal (#1056)

chore: sync public mirror from internal (#1056) #178

name: Update Nix Hash
on:
push:
branches: [main]
paths:
- 'package.json'
- 'package-lock.json'
permissions:
contents: write
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
jobs:
update-hash:
# The Nix installer creates /nix and system build users when Nix is absent.
# Keep this on a hosted runner with passwordless sudo instead of the internal
# runner, which intentionally does not allow sudo escalation.
runs-on: ubuntu-latest
timeout-minutes: 45
if: "!contains(github.event.head_commit.message, '[skip nix]')"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
token: ${{ secrets.GITHUB_TOKEN }}
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
with:
enable_kvm: false
nix_path: nixpkgs=channel:nixos-unstable
- name: Calculate new hash
id: hash
run: |
# Try to build and capture the error with expected hash
nix build .# 2>&1 | tee build.log || true
# Extract the expected hash from error message
EXPECTED_HASH=$(grep -oP 'got:\s+\K[a-zA-Z0-9+/=-]+' build.log | head -n1)
if [ -z "$EXPECTED_HASH" ]; then
echo "Could not determine hash, skipping"
exit 0
fi
echo "new_hash=$EXPECTED_HASH" >> "$GITHUB_OUTPUT"
- name: Commit hash bump
if: steps.hash.outputs.new_hash != ''
env:
NEW_HASH: ${{ steps.hash.outputs.new_hash }}
run: |
git config user.email "github-actions[bot]@users.noreply.github.com"
git config user.name "github-actions[bot]"
git checkout -B ci/update-nix-hash
sed -i "s|npmDepsHash = \"sha256-[^\"]*\"|npmDepsHash = \"${NEW_HASH}\"|" flake.nix
git add flake.nix
if git diff --cached --quiet; then
echo "No changes to commit"
exit 0
fi
git commit -m "chore: update Nix hash [skip ci]"
- name: Push hash branch (no PR)
if: steps.hash.outputs.new_hash != ''
run: |
if ! git push origin ci/update-nix-hash; then
echo "::warning::Push failed (likely concurrent update). Retrying once..."
git fetch origin ci/update-nix-hash
git rebase --autostash origin/ci/update-nix-hash
git push origin ci/update-nix-hash
fi