-
Notifications
You must be signed in to change notification settings - Fork 48
114 lines (102 loc) · 3.98 KB
/
Copy pathsync-dist.yml
File metadata and controls
114 lines (102 loc) · 3.98 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
# `dist/index.js` is what the runner actually executes, so it must always be
# the build output of the current source.
#
# Human pull requests verify their committed bundle in the CI workflow.
# Renovate pull requests are exempt from committing rebuilt dist, so this
# workflow repairs the bundle on main after Renovate changes merge.
name: Sync dist
on:
push:
branches:
- main
permissions:
contents: read
concurrency:
group: sync-dist-main
jobs:
rebuild-dist:
name: Rebuild dist
runs-on: ubuntu-24.04
timeout-minutes: 15
outputs:
base-sha: ${{ steps.rebuild.outputs.base-sha }}
changed: ${{ steps.rebuild.outputs.changed }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
cache: pnpm
cache-dependency-path: pnpm-lock.yaml
# Always rebuild against the fetched tip of main, not the trigger commit.
# This read-only job never receives permission to push repository contents.
- name: Rebuild dist against the tip of main
id: rebuild
run: |
git fetch origin main
git reset --hard FETCH_HEAD
base_sha=$(git rev-parse HEAD)
echo "base-sha=$base_sha" >> "$GITHUB_OUTPUT"
pnpm install --frozen-lockfile
pnpm build
if [ -z "$(git status --porcelain dist/)" ]; then
echo "dist matches the build output - nothing to sync"
echo "changed=false" >> "$GITHUB_OUTPUT"
exit 0
fi
echo "changed=true" >> "$GITHUB_OUTPUT"
- name: Upload rebuilt dist
if: steps.rebuild.outputs.changed == 'true'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: rebuilt-dist
path: dist/
if-no-files-found: error
retention-days: 1
sync-dist:
name: Sync dist
needs: rebuild-dist
if: needs.rebuild-dist.outputs.changed == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
ref: ${{ needs.rebuild-dist.outputs.base-sha }}
persist-credentials: false
- name: Download rebuilt dist
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: rebuilt-dist
path: dist/
- name: Commit and push rebuilt dist
shell: bash
env:
BASE_SHA: ${{ needs.rebuild-dist.outputs.base-sha }}
SYNC_DIST_GH_TOKEN: ${{ secrets.SYNC_DIST_GH_TOKEN }}
run: |
if [ -z "$SYNC_DIST_GH_TOKEN" ]; then
echo "::error::SYNC_DIST_GH_TOKEN is not configured"
exit 1
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add dist/
git commit -m "Rebuilt dist after dependency updates"
# This is a fine-grained PAT limited to this repository with only
# Contents: read and write. Its owner belongs to Ghost Foundation so
# the standard ruleset permits this generated commit on main.
auth_header=$(printf 'x-access-token:%s' "$SYNC_DIST_GH_TOKEN" | base64 | tr -d '\n')
if git -c http.https://github.com/.extraheader="AUTHORIZATION: basic $auth_header" push origin HEAD:main; then
exit 0
fi
git fetch origin main
if [ "$(git rev-parse FETCH_HEAD)" != "$BASE_SHA" ]; then
echo "main moved after the rebuild; its queued sync-dist run will rebuild the new tip"
exit 0
fi
echo "Failed to push the rebuilt dist while main was unchanged"
exit 1