fix(export): let the consumer own versions.tf (#177) #112
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Docs | |
| # Two gates over docs/handbuch/ — the section published into the Handbuch's | |
| # "ChurchTools-Grundlagen" (#89): | |
| # | |
| # 1. `build` — mkdocs --strict, so a broken link or a page missing from the nav fails | |
| # the PR here rather than silently in the consuming site build. | |
| # 2. `staleness` — reads each page's `sources:` globs and fails a PR that changes | |
| # documented code without re-signing the page. | |
| # | |
| # The staleness checker is vendored at .github/scripts/docs-staleness.mjs rather than | |
| # called as the estate-wide reusable workflow: this repo is public and a public repo | |
| # cannot call a reusable workflow out of a private one. It is a verified port of the | |
| # canonical `App\Services\Docs\SourcesHasher` and reproduces the hashes that signer | |
| # wrote, so pages stay signable from either side. | |
| # | |
| # Re-signing a page means recomputing `sources_hash` over its `sources:` — a sha256 over | |
| # each resolved file's `<relative-path>\0<contents>\0`, sorted, truncated to 16 hex chars. | |
| # Bumping `reviewed:` alone does NOT satisfy the gate; the point is that someone re-read | |
| # the page against the new code. | |
| on: | |
| push: | |
| branches: [main] | |
| paths: | |
| - "docs/handbuch/**" | |
| - "src/**" | |
| - ".github/workflows/docs.yml" | |
| - ".github/scripts/docs-staleness.mjs" | |
| pull_request: | |
| paths: | |
| - "docs/handbuch/**" | |
| - "src/**" | |
| - ".github/workflows/docs.yml" | |
| - ".github/scripts/docs-staleness.mjs" | |
| permissions: | |
| contents: read | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.12" | |
| - name: Install MkDocs | |
| run: pip install -r docs/handbuch/requirements.txt | |
| - name: Build the section (strict) | |
| run: mkdocs build -f docs/handbuch/mkdocs.yml --strict | |
| # `src/**` changed without the matching page re-signed → this fails. Signing is the | |
| # acknowledgement, not the file appearing in the diff. | |
| staleness: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22 | |
| - name: Check that documented sources are re-signed | |
| run: node .github/scripts/docs-staleness.mjs |