Merge pull request #132 from bhoy-troy/feature/cdn-deps-update-#131 #4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Check CDN Updates | |
| on: | |
| schedule: | |
| # Run every Monday at 9 AM UTC (disabled on forks) | |
| - cron: '0 9 * * 1' | |
| workflow_dispatch: # Allow manual triggering | |
| push: # Run on all branches | |
| permissions: | |
| contents: read | |
| jobs: | |
| check-cdn: | |
| name: Check CDN Dependencies | |
| runs-on: ubuntu-latest | |
| # Skip scheduled runs on forks and non-main branches | |
| if: github.event_name != 'schedule' || (github.repository == 'fedora-eln/content-resolver' && github.ref == 'refs/heads/master') | |
| outputs: | |
| exit_code: ${{ steps.check.outputs.exit_code }} | |
| has_updates: ${{ steps.check.outputs.exit_code == '1' && steps.check.outputs.error == '' }} | |
| error: ${{ steps.check.outputs.error }} | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v5 | |
| - name: Setup Python | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version: '3.14' | |
| - name: Install dependencies | |
| run: pip install beautifulsoup4 requests | |
| - name: Check for CDN updates | |
| id: check | |
| continue-on-error: true | |
| run: | | |
| set +e | |
| python3 scripts/check_cdn_updates.py | |
| EXIT_CODE=$? | |
| echo "exit_code=$EXIT_CODE" >> $GITHUB_OUTPUT | |
| # Exit codes: 0=up to date, 1=safe updates (create issue), 2=incompatible only (no issue) | |
| # Any other code is an unhandled error | |
| if [ "$EXIT_CODE" -eq 0 ] || [ "$EXIT_CODE" -eq 1 ] || [ "$EXIT_CODE" -eq 2 ]; then | |
| exit $EXIT_CODE | |
| else | |
| echo "error=Audit script failed with unexpected exit code $EXIT_CODE" >> $GITHUB_OUTPUT | |
| exit 1 | |
| fi | |
| - name: Upload report artifact | |
| if: steps.check.outputs.exit_code == '1' | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: cdn-update-report | |
| path: cdn-update-report.md | |
| retention-days: 1 | |
| - name: Summary | |
| if: always() | |
| run: | | |
| echo "## CDN Update Check Results" >> $GITHUB_STEP_SUMMARY | |
| echo "" >> $GITHUB_STEP_SUMMARY | |
| # Check for script errors | |
| if [ -n "${{ steps.check.outputs.error }}" ]; then | |
| echo "❌ **Error**: ${{ steps.check.outputs.error }}" >> $GITHUB_STEP_SUMMARY | |
| exit 1 | |
| fi | |
| # Report based on exit code | |
| if [ "${{ steps.check.outputs.exit_code }}" = "0" ]; then | |
| echo "✅ All CDN dependencies are up to date" >> $GITHUB_STEP_SUMMARY | |
| elif [ "${{ steps.check.outputs.exit_code }}" = "1" ]; then | |
| if [ -f cdn-update-report.md ]; then | |
| cat cdn-update-report.md >> $GITHUB_STEP_SUMMARY | |
| echo "" >> $GITHUB_STEP_SUMMARY | |
| echo "📦 **Safe updates available** - see report above" >> $GITHUB_STEP_SUMMARY | |
| else | |
| echo "⚠️ **Warning**: Exit code indicates updates but no report found" >> $GITHUB_STEP_SUMMARY | |
| fi | |
| elif [ "${{ steps.check.outputs.exit_code }}" = "2" ]; then | |
| if [ -f cdn-update-report.md ]; then | |
| cat cdn-update-report.md >> $GITHUB_STEP_SUMMARY | |
| echo "" >> $GITHUB_STEP_SUMMARY | |
| echo "ℹ️ **Only incompatible updates found** - see report above" >> $GITHUB_STEP_SUMMARY | |
| else | |
| echo "⚠️ **Warning**: Exit code indicates incompatible updates but no report found" >> $GITHUB_STEP_SUMMARY | |
| fi | |
| else | |
| echo "⚠️ **Unexpected exit code**: ${{ steps.check.outputs.exit_code }}" >> $GITHUB_STEP_SUMMARY | |
| fi | |
| create-issue: | |
| name: Create or Update Issue | |
| runs-on: ubuntu-latest | |
| needs: check-cdn | |
| # Only run on canonical repo master branch when updates are available | |
| if: needs.check-cdn.outputs.has_updates == 'true' && github.repository == 'fedora-eln/content-resolver' && github.ref == 'refs/heads/master' | |
| permissions: | |
| contents: read | |
| issues: write | |
| steps: | |
| - name: Download report artifact | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: cdn-update-report | |
| - name: Create or update issue | |
| uses: actions/github-script@v8 | |
| with: | |
| script: | | |
| const fs = require('fs'); | |
| // Read the report generated by the check job | |
| let report; | |
| try { | |
| report = fs.readFileSync('cdn-update-report.md', 'utf8'); | |
| } catch (error) { | |
| console.log('No report file found'); | |
| return; | |
| } | |
| // Check for existing open issue | |
| const issues = await github.rest.issues.listForRepo({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| state: 'open', | |
| labels: 'dependencies,cdn' | |
| }); | |
| const existingIssue = issues.data.find(issue => | |
| issue.title.includes('CDN Dependency Updates') | |
| ); | |
| const timestamp = new Date().toISOString().split('T')[0]; | |
| if (existingIssue) { | |
| // Update existing issue with new comment | |
| await github.rest.issues.createComment({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| issue_number: existingIssue.number, | |
| body: `## 🔄 Update Check - ${timestamp}\n\n${report}` | |
| }); | |
| console.log(`Updated existing issue #${existingIssue.number}`); | |
| } else { | |
| // Create new issue | |
| await github.rest.issues.create({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| title: '🔄 CDN Dependency Updates Available', | |
| body: report, | |
| labels: ['dependencies', 'cdn', 'enhancement'] | |
| }); | |
| console.log('Created new issue for CDN updates'); | |
| } |