-
Notifications
You must be signed in to change notification settings - Fork 0
105 lines (92 loc) · 3.99 KB
/
Copy pathopenapi-sync.yml
File metadata and controls
105 lines (92 loc) · 3.99 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
name: Sync OpenAPI contract
on:
schedule:
- cron: "23 4 * * *"
workflow_dispatch:
inputs:
server_sha:
description: Exact Life-USTC/server commit SHA (defaults to current main)
required: false
type: string
permissions:
contents: write
pull-requests: write
concurrency:
group: openapi-contract-sync
cancel-in-progress: false
jobs:
sync:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Resolve immutable server commit
id: server
env:
INPUT_SHA: ${{ inputs.server_sha }}
run: |
explicit="${INPUT_SHA:-}"
if [[ -n "$explicit" ]]; then
if [[ ! "$explicit" =~ ^[0-9a-f]{40}$ ]]; then
echo "Explicit server_sha must be an exact 40-character lowercase commit SHA" >&2
exit 1
fi
sha="$explicit"
else
sha="$(git ls-remote https://github.com/Life-USTC/server.git refs/heads/main | awk '{print $1}')"
if [[ ! "$sha" =~ ^[0-9a-f]{40}$ ]]; then
echo "Could not resolve Life-USTC/server main to an immutable commit" >&2
exit 1
fi
fi
echo "sha=$sha" >> "$GITHUB_OUTPUT"
- name: Checkout exact server commit
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: Life-USTC/server
ref: ${{ steps.server.outputs.sha }}
path: .openapi-server
# Needed so the sync refuses to pin a commit that never landed on
# server main (a pull-request head stays fetchable by SHA forever).
fetch-depth: 0
- name: Fetch server main for the pin reachability check
run: |
git -C .openapi-server fetch --no-tags --quiet origin \
+refs/heads/main:refs/remotes/origin/main
git -C .openapi-server rev-parse --verify refs/remotes/origin/main >/dev/null
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
- name: Sync contract and generated client
run: |
test "$(git -C .openapi-server rev-parse HEAD)" = "${{ steps.server.outputs.sha }}"
if ./scripts/openapi-contract verify >/dev/null 2>&1 \
&& ./scripts/openapi-contract verify-reachable .openapi-server >/dev/null 2>&1 \
&& cmp -s .openapi-server/public/openapi.generated.json api/openapi.json; then
echo "Server contract is unchanged; preserving the existing provenance pin." >> "$GITHUB_STEP_SUMMARY"
else
make sync-openapi OPENAPI_SERVER_DIR=.openapi-server SERVER_COMMIT=${{ steps.server.outputs.sha }}
make check-openapi-sync OPENAPI_SERVER_DIR=.openapi-server
fi
make generate
- name: Build, test, and vet
run: |
make build
make test
make vet
- name: golangci-lint
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
with:
version: v2.12.2
# Set OPENAPI_SYNC_TOKEN to a PAT or GitHub App token if automated PRs
# should trigger the repository's normal pull_request workflows.
- name: Open or update contract PR
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
token: ${{ secrets.OPENAPI_SYNC_TOKEN || github.token }}
branch: automation/openapi-contract
delete-branch: true
commit-message: "chore: sync OpenAPI contract"
title: "chore: sync OpenAPI contract"
body: |
Synchronizes the vendored OpenAPI contract and generated CLI client with an immutable `Life-USTC/server` commit.
The sync workflow completed build, race-enabled tests, vet, and lint before opening this PR. When it uses the default `GITHUB_TOKEN`, GitHub will not trigger a second pull-request CI run.