Repository navigation
Refresh release & star data #49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Refresh release & star data | |
| on: | |
| # Runs 30 minutes before deploy.yml's daily 06:17 UTC rebuild so the committed | |
| # fallback data is fresh when that build runs. The push below uses the default | |
| # GITHUB_TOKEN, which by design does not retrigger other workflows — no double | |
| # deploy; the deploy cron (which also re-runs this script at build time) picks | |
| # the commit up. | |
| schedule: | |
| - cron: "47 5 * * *" | |
| workflow_dispatch: | |
| # Least-privilege floor: only the refresh job below needs contents:write to | |
| # push the updated data files. (zizmor: excessive-permissions) | |
| permissions: {} | |
| defaults: | |
| run: | |
| shell: bash | |
| jobs: | |
| refresh: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false # zizmor: artipacked; the push authenticates explicitly below | |
| - name: Refresh data/releases.json and data/stars.json | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: python3 scripts/refresh-releases.py | |
| - name: Commit and push if changed | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| if git diff --quiet -- data/; then | |
| echo "Data unchanged; nothing to commit." | |
| exit 0 | |
| fi | |
| git config user.name "github-actions[bot]" | |
| git config user.email "41898282+github-actions[bot]@users.noreply.github.com" | |
| git add data/releases.json data/stars.json | |
| git commit -m "data: daily refresh of release tags and star counts" | |
| git push "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:main |