diff --git a/.github/workflows/automated.yaml b/.github/workflows/automated.yaml index 110aedb..4b38699 100644 --- a/.github/workflows/automated.yaml +++ b/.github/workflows/automated.yaml @@ -1,5 +1,11 @@ name: Automated on: + push: + paths: + - "pnpm-lock.yaml" + - "package.json" + branches: + - "main" schedule: - cron: "0 8 * * 0" workflow_dispatch: @@ -9,13 +15,14 @@ concurrency: cancel-in-progress: true permissions: - actions: write # Allow canceling in-progress runs - contents: write # Read/write access to the repository - pull-requests: write # Allow creating pull requests + actions: write + contents: write + pull-requests: write jobs: - flake-inputs: - name: flake-inputs + nix-pnpm-hash: + name: Update Nix PNPM Hash + if: github.event_name == 'push' || github.event_name == 'workflow_dispatch' runs-on: ubuntu-latest steps: - name: Check out the repo @@ -26,7 +33,57 @@ jobs: with: determinate: true - - uses: DeterminateSystems/update-flake-lock@main + - name: Cache Nix store + uses: DeterminateSystems/magic-nix-cache-action@main + + - name: Compute correct PNPM dependencies hash + id: hash + run: | + CURRENT_HASH=$(grep -oP "hash = \"\K[^\"]*" nix/package.nix) + sed -i "s|hash = \"$CURRENT_HASH\"|hash = \"\"|" nix/package.nix + + NEW_HASH=$(nix build .#headplane.pnpmDeps --no-link 2>&1 \ + | grep 'got:' \ + | awk '{print $2}') + + if [ -z "$NEW_HASH" ]; then + echo "Hash is already up to date" + echo "changed=false" >> "$GITHUB_OUTPUT" + exit 0 + fi + + echo "new_hash=$NEW_HASH" >> "$GITHUB_OUTPUT" + echo "changed=true" >> "$GITHUB_OUTPUT" + + - name: Update hash in package.nix + if: steps.hash.outputs.changed == 'true' + run: | + sed -i "s|hash = \"\"|hash = \"${{ steps.hash.outputs.new_hash }}\"|" nix/package.nix + + - name: Commit and push + if: steps.hash.outputs.changed == 'true' + run: | + git config user.name "github-actions[bot]" + git config user.email "github-actions[bot]@users.noreply.github.com" + git add nix/package.nix + git commit -m "chore: update nix pnpm deps hash" + git push + + flake-inputs: + name: Update Flake Inputs + if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' + runs-on: ubuntu-latest + steps: + - name: Check out the repo + uses: actions/checkout@v6 + + - name: Install Nix + uses: DeterminateSystems/nix-installer-action@main + with: + determinate: true + + - name: Update flake.lock + uses: DeterminateSystems/update-flake-lock@main with: pr-title: "chore: update flake.lock" pr-labels: | diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index f1f11a9..f0c721f 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -15,8 +15,8 @@ concurrency: cancel-in-progress: true permissions: - actions: write # Allow canceling in-progress runs - contents: read # Read access to the repository + actions: write + contents: read jobs: ci: @@ -41,8 +41,9 @@ jobs: uses: actions/setup-go@v6 with: go-version-file: go.mod + cache: true - - name: CI pipeline + - name: Build run: ./build.sh --skip-pnpm-prune - name: Run unit tests @@ -52,7 +53,7 @@ jobs: run: pnpm run test:integration nix: - name: nix + name: Nix Flake Check runs-on: ubuntu-latest steps: - name: Check out the repo @@ -63,8 +64,11 @@ jobs: with: determinate: true + - name: Cache Nix store + uses: DeterminateSystems/magic-nix-cache-action@main + - name: Check flake inputs uses: DeterminateSystems/flake-checker-action@main - name: Check flake outputs - run: nix flake check --all-systems + run: nix flake check diff --git a/.github/workflows/labeler.yaml b/.github/workflows/labeler.yaml index 155f4da..eceacff 100644 --- a/.github/workflows/labeler.yaml +++ b/.github/workflows/labeler.yaml @@ -9,9 +9,10 @@ permissions: jobs: label: - name: Label PR + name: Label Pull Request runs-on: ubuntu-latest steps: - - uses: actions/labeler@v6 + - name: Apply labels based on changed files + uses: actions/labeler@v6 with: sync-labels: true diff --git a/.github/workflows/lifecycle.yaml b/.github/workflows/lifecycle.yaml index a31e66d..04658db 100644 --- a/.github/workflows/lifecycle.yaml +++ b/.github/workflows/lifecycle.yaml @@ -9,11 +9,12 @@ permissions: jobs: beta: - name: Beta Release + name: Beta Release Lifecycle if: contains(github.ref_name, '-') runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - name: Check out the repo + uses: actions/checkout@v6 with: fetch-depth: 0 @@ -48,7 +49,7 @@ jobs: done stable: - name: Stable Release + name: Stable Release Lifecycle if: ${{ !contains(github.ref_name, '-') }} runs-on: ubuntu-latest steps: diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 6572118..a11b083 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -9,15 +9,15 @@ concurrency: cancel-in-progress: true permissions: - actions: write # Allow canceling in-progress runs - contents: read # Read access to the repository - packages: write # Write access to the container registry - id-token: write # For the attest action to push - attestations: write # For the attest action to push + actions: write + contents: read + packages: write + id-token: write + attestations: write jobs: docker: - name: Docker Release + name: Docker Release (${{ matrix.target }}) runs-on: ubuntu-latest strategy: matrix: @@ -26,12 +26,11 @@ jobs: tag_suffix: "" - target: debug-shell tag_suffix: "-shell" - steps: - name: Check out the repo uses: actions/checkout@v6 - - name: Docker Metadata + - name: Extract Docker metadata id: meta uses: docker/metadata-action@v5 with: @@ -55,9 +54,9 @@ jobs: username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - name: Build and push ${{ fromJSON(steps.meta.outputs.json).tags[0] }} - uses: docker/build-push-action@v6 + - name: Build and push id: push + uses: docker/build-push-action@v6 with: context: . file: ./Dockerfile @@ -71,9 +70,9 @@ jobs: build-args: | IMAGE_TAG=ghcr.io/${{ github.repository }}:${{ fromJSON(steps.meta.outputs.json).labels['org.opencontainers.image.version'] }} HEADPLANE_VERSION=${{ fromJSON(steps.meta.outputs.json).labels['org.opencontainers.image.version'] }} - - name: Attestation Provenance for ${{ fromJSON(steps.meta.outputs.json).tags[0] }} + + - name: Attest build provenance uses: actions/attest-build-provenance@v2 - id: attest with: subject-name: ghcr.io/${{ github.repository }} subject-digest: ${{ steps.push.outputs.digest }} diff --git a/.github/workflows/stale.yaml b/.github/workflows/stale.yaml index 30a1666..534a685 100644 --- a/.github/workflows/stale.yaml +++ b/.github/workflows/stale.yaml @@ -10,10 +10,11 @@ permissions: jobs: stale: - name: Close stale issues + name: Close Stale Issues runs-on: ubuntu-latest steps: - - uses: actions/stale@v10 + - name: Mark and close stale issues + uses: actions/stale@v10 with: stale-issue-label: Stale only-labels: "Needs Info" diff --git a/.github/workflows/triage.yaml b/.github/workflows/triage.yaml index 5b52e6f..1303706 100644 --- a/.github/workflows/triage.yaml +++ b/.github/workflows/triage.yaml @@ -8,7 +8,7 @@ permissions: jobs: remove-triage: - name: Remove Needs Triage + name: Remove Needs Triage Label runs-on: ubuntu-latest steps: - name: Remove Needs Triage label diff --git a/nix/package.nix b/nix/package.nix index 2820caf..b0b037c 100644 --- a/nix/package.nix +++ b/nix/package.nix @@ -28,8 +28,8 @@ in pnpmDeps = pnpm_10.fetchDeps { inherit (finalAttrs) pname version src; - hash = "sha256-Xtooqpibv4fuJczUfJDlGt2+5KuoKq/TUUhLKE+ierA="; - fetcherVersion = 1; + fetcherVersion = 3; + hash = "sha256-aZFExHeZm5Ga2OjmKMUmkJ78KTphVi01d4dYoMPnmOs="; }; buildPhase = ''