tooling-pin-check #9
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Detects when newer versions of the development tooling pinned outside any | |
| # Dependabot-readable manifest are available, and raises a PR bumping them for | |
| # evaluation. | |
| # | |
| # What it covers (and why Dependabot can't): | |
| # - @playwright/mcp, pinned in BOTH .devcontainer/setup.sh and .mcp.json. These | |
| # live in a shell script and an MCP config, not a package.json, so Dependabot's | |
| # npm ecosystem never sees them. The two pins must move in lockstep or the | |
| # installed browser and the MCP server drift apart. | |
| # - dotnet-ef, installed via `dotnet tool install` in .devcontainer/setup.sh. | |
| # Not a .csproj reference, so Dependabot's nuget ecosystem never sees it. | |
| # | |
| # See .github/scripts/check-tooling-pins.ps1 (detection: npm/NuGet registry | |
| # lookups, no Docker) and .github/scripts/open-pin-pr.ps1 (the shared | |
| # signed-commit PR opener, also used by apt-pin-check). | |
| # | |
| # Identity / token choice is identical to apt-pin-check: the PR is opened by the | |
| # jim-automation GitHub App, not the default GITHUB_TOKEN. Two reasons: | |
| # 1. `main` requires signed commits; commits created via the GitHub API (the | |
| # GraphQL createCommitOnBranch mutation in open-pin-pr.ps1) are signed by | |
| # GitHub, and an App installation token authorises them. | |
| # 2. A PR opened with GITHUB_TOKEN does NOT trigger the required-check | |
| # workflows, so it could never satisfy branch protection. App-authored | |
| # events DO trigger them, so the bump PR runs CI and can merge. | |
| # The App's credentials are reused from apt-pin-check (JIM_AUTOMATION_APP_ID / | |
| # JIM_AUTOMATION_PRIVATE_KEY); the App is already scoped to Contents and Pull | |
| # requests (read/write) on this repository, which is all this workflow needs. | |
| name: tooling-pin-check | |
| on: | |
| schedule: | |
| # Weekly, Mondays at 06:00 UTC. Dev tooling moves far slower than the daily | |
| # Ubuntu archive the apt check watches, so a weekly poll is ample. | |
| - cron: '0 6 * * 1' | |
| workflow_dispatch: | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| concurrency: | |
| group: tooling-pin-check | |
| cancel-in-progress: true | |
| jobs: | |
| check: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 | |
| - name: Detect and apply available tooling pin updates | |
| id: check | |
| shell: pwsh | |
| run: | | |
| ./.github/scripts/check-tooling-pins.ps1 -Apply | |
| # Exit 2 means "updates applied"; treat as success for the workflow. | |
| if ($LASTEXITCODE -eq 2) { exit 0 } | |
| exit $LASTEXITCODE | |
| - name: Mint GitHub App installation token | |
| if: steps.check.outputs.has_updates == 'true' | |
| id: app-token | |
| uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 | |
| with: | |
| app-id: ${{ secrets.JIM_AUTOMATION_APP_ID }} | |
| private-key: ${{ secrets.JIM_AUTOMATION_PRIVATE_KEY }} | |
| - name: Open or update bump PR | |
| if: steps.check.outputs.has_updates == 'true' | |
| shell: pwsh | |
| env: | |
| GH_TOKEN: ${{ steps.app-token.outputs.token }} | |
| GITHUB_REPOSITORY: ${{ github.repository }} | |
| run: | | |
| $intro = @' | |
| Newer versions of development tooling pinned outside any Dependabot-readable | |
| manifest (.devcontainer/setup.sh, .mcp.json) are available upstream. Raised | |
| for evaluation by the tooling-pin-check workflow. Where a tool is pinned in | |
| more than one file, every location has been moved to the same version. | |
| '@ | |
| ./.github/scripts/open-pin-pr.ps1 ` | |
| -BodyFile tooling-pin-pr-body.md ` | |
| -FilePattern '(^|/)(setup\.sh|\.mcp\.json)$' ` | |
| -Branch 'automation/tooling-pin-updates' ` | |
| -CommitHeadline 'chore(deps): bump pinned development tooling versions' ` | |
| -CommitBodyIntro $intro ` | |
| -Label 'dependencies' |