mirror of
https://github.com/okxlin/appstore.git
synced 2026-10-01 00:00:11 +00:00
106 lines
3.7 KiB
YAML
106 lines
3.7 KiB
YAML
name: Guard Renovate sidecar-only updates
|
|
|
|
on:
|
|
pull_request:
|
|
types: [opened, synchronize, reopened]
|
|
branches:
|
|
- localApps
|
|
workflow_dispatch:
|
|
inputs:
|
|
pr_number:
|
|
description: Existing Renovate PR number to evaluate
|
|
required: true
|
|
type: string
|
|
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
jobs:
|
|
guard:
|
|
if: >
|
|
(
|
|
github.event_name == 'pull_request' &&
|
|
github.event.pull_request.state == 'open' &&
|
|
(
|
|
github.event.pull_request.user.login == 'app/renovate' ||
|
|
github.event.pull_request.user.login == 'renovate[bot]' ||
|
|
(
|
|
github.event.pull_request.head.repo.full_name == github.repository &&
|
|
(
|
|
startsWith(github.event.pull_request.head.ref, 'renovate/') ||
|
|
startsWith(github.event.pull_request.head.ref, 'selfhosted-renovate/')
|
|
)
|
|
)
|
|
)
|
|
) || (
|
|
github.event_name == 'workflow_dispatch'
|
|
)
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Ensure PyYAML is available
|
|
run: |
|
|
python3 - <<'PY'
|
|
import importlib.util
|
|
import subprocess
|
|
import sys
|
|
|
|
if importlib.util.find_spec("yaml") is None:
|
|
subprocess.check_call([sys.executable, "-m", "pip", "install", "--user", "pyyaml"])
|
|
PY
|
|
|
|
- name: Evaluate Renovate PR against primary-service policy
|
|
id: guard
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
run: |
|
|
python3 .github/scripts/renovate_sidecar_guard.py \
|
|
--repo "${{ github.repository }}" \
|
|
--pr "${{ github.event.pull_request.number || inputs.pr_number }}" \
|
|
--policy-file .github/renovate-primary-services.json \
|
|
> /tmp/renovate-sidecar-guard.json
|
|
|
|
cat /tmp/renovate-sidecar-guard.json
|
|
echo "decision=$(jq -r '.decision' /tmp/renovate-sidecar-guard.json)" >> "$GITHUB_OUTPUT"
|
|
{
|
|
echo 'reason<<EOF'
|
|
jq -r '.reason' /tmp/renovate-sidecar-guard.json
|
|
echo 'EOF'
|
|
} >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Comment and close sidecar-only PR
|
|
if: steps.guard.outputs.decision == 'close'
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
run: |
|
|
pr_number="${{ github.event.pull_request.number || inputs.pr_number }}"
|
|
reason="${{ steps.guard.outputs.reason }}"
|
|
|
|
gh pr comment "$pr_number" \
|
|
--repo "${{ github.repository }}" \
|
|
--body "Closing this Renovate PR automatically because it updates only auxiliary service image tags in a multi-service app and does not include any configured primary service image update.\n\nReason: ${reason}\n\nIf we decide to move this sidecar version intentionally, we can reopen or submit a maintainer PR with tested upgrade evidence."
|
|
|
|
gh pr close "$pr_number" \
|
|
--repo "${{ github.repository }}"
|
|
|
|
REPO="${{ github.repository }}"
|
|
pr_head=$(gh api "repos/$REPO/pulls/$pr_number" \
|
|
--jq '[.head.repo.full_name, .head.ref] | @tsv')
|
|
IFS=$'\t' read -r head_repo head_ref <<< "$pr_head"
|
|
|
|
if [[ "$head_repo" == "$REPO" ]]; then
|
|
case "$head_ref" in
|
|
selfhosted-renovate/*|renovate/*)
|
|
if ! gh api --method DELETE "repos/$REPO/git/refs/heads/$head_ref"; then
|
|
echo "::notice::Renovate branch was already removed or could not be deleted: $head_ref"
|
|
fi
|
|
;;
|
|
esac
|
|
fi
|