-
-
Notifications
You must be signed in to change notification settings - Fork 0
136 lines (135 loc) · 4.74 KB
/
Copy pathdependabot-packages.yml
File metadata and controls
136 lines (135 loc) · 4.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
# Dependabot
#
# Run commands for @dependabot on package update.
#
# Note: The `dedupe` job can be removed once dependabot supports automatic deduplication.
# See https://github.com/dependabot/dependabot-core/issues/5830 for details.
#
# References:
#
# - https://docs.github.com/actions/learn-github-actions/contexts
# - https://docs.github.com/actions/learn-github-actions/expressions
# - https://docs.github.com/actions/using-workflows/events-that-trigger-workflows#pull_request
# - https://docs.github.com/code-security/dependabot/working-with-dependabot/automating-dependabot-with-github-actions
# - https://docs.github.com/webhooks-and-events/webhooks/webhook-events-and-payloads#pull_request
# - https://github.com/actions/checkout
# - https://github.com/actions/create-github-app-token
# - https://github.com/actions/setup-node
# - https://github.com/actions/setup-node/blob/main/docs/advanced-usage.md#yarn2-configuration
# - https://github.com/dependabot/fetch-metadata
# - https://github.com/flex-development/gh-commit
# - https://github.com/hmarr/debug-action
---
name: dependabot-packages
on:
pull_request:
branches:
- main
concurrency:
cancel-in-progress: true
group: ${{ github.workflow }}-${{ github.ref }}
jobs:
preflight:
if: |
${{ github.actor == vars.DEPENDABOT
&& startsWith(github.head_ref, 'dependabot/npm_and_yarn/') }}
runs-on: ubuntu-latest
outputs:
packages: ${{ steps.metadata.outputs.dependency-names }}
steps:
- id: debug
name: Print environment variables and event payload
uses: hmarr/debug-action@v3.0.0
- id: bot-token
name: Get bot token
uses: actions/create-github-app-token@v3.2.0
with:
client-id: ${{ secrets.BOT_APP_ID }}
private-key: ${{ secrets.BOT_PRIVATE_KEY }}
- id: metadata
name: Fetch metadata
uses: dependabot/fetch-metadata@v3.1.0
with:
github-token: ${{ steps.bot-token.outputs.token }}
dedupe:
needs: preflight
runs-on: ubuntu-latest
steps:
- id: bot-token
name: Get bot token
uses: actions/create-github-app-token@v3.2.0
with:
client-id: ${{ secrets.BOT_APP_ID }}
private-key: ${{ secrets.BOT_PRIVATE_KEY }}
- id: checkout
name: Checkout ${{ github.head_ref }}
uses: actions/checkout@v7.0.1
with:
persist-credentials: false
ref: ${{ github.head_ref }}
token: ${{ steps.bot-token.outputs.token }}
- id: node
name: Setup Node.js
uses: actions/setup-node@v7.0.0
with:
cache: yarn
cache-dependency-path: yarn.lock
node-version-file: .nvmrc
- id: dedupe
name: Deduplicate dependencies
env:
YARN_ENABLE_GLOBAL_CACHE: true
YARN_ENABLE_IMMUTABLE_INSTALLS: false
YARN_ENABLE_SCRIPTS: false
run: yarn dedupe --mode=update-lockfile
- id: status
name: Print git status
run: git status --porcelain
- id: commit
name: Commit and push yarn.lock
uses: flex-development/gh-commit@1.0.0
with:
message: 'build(yarn): [dependabot skip] deduplicate dependencies for @dependabot'
token: ${{ steps.bot-token.outputs.token }}
trailers: 'Signed-off-by: ${{ vars.BOT_NAME }} <${{ vars.BOT_EMAIL }}>'
dprint:
if: ${{ contains(needs.preflight.outputs.packages, 'dprint') }}
needs:
- dedupe
- preflight
runs-on: ubuntu-latest
steps:
- id: bot-token
name: Get bot token
uses: actions/create-github-app-token@v3.2.0
with:
client-id: ${{ secrets.BOT_APP_ID }}
private-key: ${{ secrets.BOT_PRIVATE_KEY }}
- id: checkout
name: Checkout ${{ github.head_ref }}
uses: actions/checkout@v7.0.1
with:
persist-credentials: false
ref: ${{ github.head_ref }}
token: ${{ steps.bot-token.outputs.token }}
- id: dependencies
name: Install dependencies
env:
YARN_ENABLE_IMMUTABLE_INSTALLS: false
run: yarn
- id: local-binaries
name: Add local binaries to $PATH
run: echo "$GITHUB_WORKSPACE/node_modules/.bin" >> $GITHUB_PATH
- id: dprint
name: Update dprint config
run: dprint config update --yes
- id: status
name: Print git status
run: git status --porcelain
- id: commit
name: Commit and push dprint config update
uses: flex-development/gh-commit@1.0.0
with:
message: 'chore: [dependabot skip] run `dprint config update` for @dependabot'
token: ${{ steps.bot-token.outputs.token }}
trailers: 'Signed-off-by: ${{ vars.BOT_NAME }} <${{ vars.BOT_EMAIL }}>'