Skip to content

tooling-pin-check

tooling-pin-check #9

# Detects when newer versions of the development tooling pinned outside any
# Dependabot-readable manifest are available, and raises a PR bumping them for
# evaluation.
#
# What it covers (and why Dependabot can't):
# - @playwright/mcp, pinned in BOTH .devcontainer/setup.sh and .mcp.json. These
# live in a shell script and an MCP config, not a package.json, so Dependabot's
# npm ecosystem never sees them. The two pins must move in lockstep or the
# installed browser and the MCP server drift apart.
# - dotnet-ef, installed via `dotnet tool install` in .devcontainer/setup.sh.
# Not a .csproj reference, so Dependabot's nuget ecosystem never sees it.
#
# See .github/scripts/check-tooling-pins.ps1 (detection: npm/NuGet registry
# lookups, no Docker) and .github/scripts/open-pin-pr.ps1 (the shared
# signed-commit PR opener, also used by apt-pin-check).
#
# Identity / token choice is identical to apt-pin-check: the PR is opened by the
# jim-automation GitHub App, not the default GITHUB_TOKEN. Two reasons:
# 1. `main` requires signed commits; commits created via the GitHub API (the
# GraphQL createCommitOnBranch mutation in open-pin-pr.ps1) are signed by
# GitHub, and an App installation token authorises them.
# 2. A PR opened with GITHUB_TOKEN does NOT trigger the required-check
# workflows, so it could never satisfy branch protection. App-authored
# events DO trigger them, so the bump PR runs CI and can merge.
# The App's credentials are reused from apt-pin-check (JIM_AUTOMATION_APP_ID /
# JIM_AUTOMATION_PRIVATE_KEY); the App is already scoped to Contents and Pull
# requests (read/write) on this repository, which is all this workflow needs.
name: tooling-pin-check
on:
schedule:
# Weekly, Mondays at 06:00 UTC. Dev tooling moves far slower than the daily
# Ubuntu archive the apt check watches, so a weekly poll is ample.
- cron: '0 6 * * 1'
workflow_dispatch:
permissions:
contents: write
pull-requests: write
concurrency:
group: tooling-pin-check
cancel-in-progress: true
jobs:
check:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- name: Detect and apply available tooling pin updates
id: check
shell: pwsh
run: |
./.github/scripts/check-tooling-pins.ps1 -Apply
# Exit 2 means "updates applied"; treat as success for the workflow.
if ($LASTEXITCODE -eq 2) { exit 0 }
exit $LASTEXITCODE
- name: Mint GitHub App installation token
if: steps.check.outputs.has_updates == 'true'
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
app-id: ${{ secrets.JIM_AUTOMATION_APP_ID }}
private-key: ${{ secrets.JIM_AUTOMATION_PRIVATE_KEY }}
- name: Open or update bump PR
if: steps.check.outputs.has_updates == 'true'
shell: pwsh
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
GITHUB_REPOSITORY: ${{ github.repository }}
run: |
$intro = @'
Newer versions of development tooling pinned outside any Dependabot-readable
manifest (.devcontainer/setup.sh, .mcp.json) are available upstream. Raised
for evaluation by the tooling-pin-check workflow. Where a tool is pinned in
more than one file, every location has been moved to the same version.
'@
./.github/scripts/open-pin-pr.ps1 `
-BodyFile tooling-pin-pr-body.md `
-FilePattern '(^|/)(setup\.sh|\.mcp\.json)$' `
-Branch 'automation/tooling-pin-updates' `
-CommitHeadline 'chore(deps): bump pinned development tooling versions' `
-CommitBodyIntro $intro `
-Label 'dependencies'