From 2666e33feade24b9c3a80574a5cd673643c1ee53 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 17:24:31 -0300 Subject: [PATCH 1/5] ci: restore workflow synchronization Signed-off-by: Vitor Mattos --- .github/workflows/sync-workflow-templates.yml | 152 ++++++++++++++++++ 1 file changed, 152 insertions(+) create mode 100644 .github/workflows/sync-workflow-templates.yml diff --git a/.github/workflows/sync-workflow-templates.yml b/.github/workflows/sync-workflow-templates.yml new file mode 100644 index 0000000..230a0ef --- /dev/null +++ b/.github/workflows/sync-workflow-templates.yml @@ -0,0 +1,152 @@ +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors +# SPDX-License-Identifier: MIT + +# This workflow will update all workflow templates +# Additionally it will reapply `workflow.yml.patch` files after syncing and only then commit the result +name: Update workflows +on: + workflow_dispatch: + schedule: + - cron: "5 2 * * 0" + +permissions: + contents: read + +jobs: + dispatch: + runs-on: ubuntu-latest + + strategy: + fail-fast: false + matrix: + branches: + - ${{ github.event.repository.default_branch }} + - 'stable32' + - 'stable31' + + name: Update workflows in ${{ matrix.branches }} + + permissions: + contents: write + pull-requests: write + + steps: + - name: Check actor permission + uses: skjnldsv/check-actor-permission@69e92a3c4711150929bca9fcf34448c5bf5526e7 # v3.0 + with: + require: admin + + - name: Create GitHub App token + id: app-token + uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + with: + app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} + owner: LibreCodeCoop + repositories: ${{ github.event.repository.name }} + permission-contents: write + permission-pull-requests: write + permission-workflows: write + + - name: Checkout workflow repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + path: source + repository: LibreCodeCoop/.github + + - name: Checkout app + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + path: target + ref: ${{ matrix.branches }} + + - name: Copy all workflow templates + run: | + echo 'SUMMARY<> $GITHUB_ENV + draft_only=0 + for workflow in ./source/workflow-templates/*.yml; do + echo "❓ Looking for $workflow" + if [ -f "$workflow" ]; then + filename=$(basename "$workflow") + target_file="./target/.github/workflows/$filename" + + # Only copy if the file exists in the target repository + if [ -f "$target_file" ]; then + if [ -f "./target/.github/actions-lock.txt" ]; then + locked_version=$(grep " $filename" ./target/.github/actions-lock.txt | cat) + else + echo "# SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors" >> ./target/.github/actions-lock.txt + echo "# SPDX-License""-Identifier: MIT" >> ./target/.github/actions-lock.txt + locked_version="" + fi + locked_version=$(echo $locked_version | cut -f 1 -d " ") + new_version=$(md5sum $workflow | cut -f 1 -d " ") + + # Only update if the action changes + if [[ "$locked_version" != "$new_version" ]]; then + echo "ℹ️ Locked version: $locked_version" + echo "ℹ️ Current version: $new_version" + echo "🆙 Updating existing workflow: $filename" + echo "- 🆙 Updated [$filename](https://github.com/LibreCodeCoop/.github/commits/main/workflow-templates/$filename)" >> $GITHUB_ENV + + cp "$workflow" "$target_file" + + # Apply patch if one exists + if [ -f "$target_file.patch" ]; then + echo "🩹 Applying patch" + cd ./target + set +e + patch -p1 < ".github/workflows/$filename.patch" + patch_worked=$? + set -e + cd - + if [[ "$patch_worked" == "0" ]]; then + echo " - Patch applied" >> $GITHUB_ENV + else + echo " - [ ] ❌ Patch failed" >> $GITHUB_ENV + draft_only=1 + fi + fi + + if [[ "$locked_version" != "" ]]; then + sed -i "s/$locked_version $filename/$new_version $filename/" ./target/.github/actions-lock.txt + else + echo "$new_version $filename" >> ./target/.github/actions-lock.txt + fi + else + echo "✅ Skipping $filename: already up to date" + fi + else + echo "⏭️ Skipping $filename: does not exist in target repository" + fi + fi + done + echo 'EOF' >> $GITHUB_ENV + echo "DRAFT_ONLY=${draft_only}" >> $GITHUB_ENV + + - name: Create Pull Request + uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 + with: + token: ${{ steps.app-token.outputs.token }} + commit-message: 'ci(actions): Update workflow templates from organization template repository' + committer: GitHub + author: librecode-workflow-automation[bot] <331658022+librecode-workflow-automation[bot]@users.noreply.github.com> + path: target + signoff: true + branch: 'automated/noid/${{ matrix.branches }}-update-workflows' + title: '[${{ matrix.branches }}] ci(actions): Update workflow templates from organization template repository' + draft: ${{ env.DRAFT_ONLY == 1 }} + add-paths: .github/workflows/*.yml,.github/actions-lock.txt + body: | + Automated update of all workflow templates from [LibreCodeCoop/.github](https://github.com/LibreCodeCoop/.github) + ${{ env.SUMMARY }} + labels: | + dependencies + 3. to review From d64d49d011416fccf5669f5ea03720c626c2690d Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 17:24:33 -0300 Subject: [PATCH 2/5] ci: add extract workflow sync patch Signed-off-by: Vitor Mattos --- .github/workflows/sync-workflow-templates.yml.patch | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 .github/workflows/sync-workflow-templates.yml.patch diff --git a/.github/workflows/sync-workflow-templates.yml.patch b/.github/workflows/sync-workflow-templates.yml.patch new file mode 100644 index 0000000..7a0da26 --- /dev/null +++ b/.github/workflows/sync-workflow-templates.yml.patch @@ -0,0 +1,13 @@ +--- .github/workflows/sync-workflow-templates.yml ++++ .github/workflows/sync-workflow-templates.yml +@@ -28,9 +28,8 @@ + matrix: + branches: + - ${{ github.event.repository.default_branch }} +- - 'stable35' +- - 'stable34' +- - 'stable33' ++ - 'stable32' ++ - 'stable31' + + name: Update workflows in ${{ matrix.branches }} From 629faa9b2e7d123e9799ca647d67ea243bad8147 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 17:24:45 -0300 Subject: [PATCH 3/5] chore: license workflow sync patch Signed-off-by: Vitor Mattos --- .github/workflows/sync-workflow-templates.yml.patch.license | 2 ++ 1 file changed, 2 insertions(+) create mode 100644 .github/workflows/sync-workflow-templates.yml.patch.license diff --git a/.github/workflows/sync-workflow-templates.yml.patch.license b/.github/workflows/sync-workflow-templates.yml.patch.license new file mode 100644 index 0000000..1ce4e0c --- /dev/null +++ b/.github/workflows/sync-workflow-templates.yml.patch.license @@ -0,0 +1,2 @@ +SPDX-FileCopyrightText: 2026 LibreCode coop and contributors +SPDX-License-Identifier: AGPL-3.0-or-later From 63cb9900b060b0eb0845c2600ac725499d4d8118 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 18:23:25 -0300 Subject: [PATCH 4/5] ci: use reusable workflow sync action Signed-off-by: Vitor Mattos --- .github/workflows/sync-workflow-templates.yml | 76 +++---------------- 1 file changed, 9 insertions(+), 67 deletions(-) diff --git a/.github/workflows/sync-workflow-templates.yml b/.github/workflows/sync-workflow-templates.yml index 230a0ef..d6fbc8e 100644 --- a/.github/workflows/sync-workflow-templates.yml +++ b/.github/workflows/sync-workflow-templates.yml @@ -26,8 +26,6 @@ jobs: matrix: branches: - ${{ github.event.repository.default_branch }} - - 'stable32' - - 'stable31' name: Update workflows in ${{ matrix.branches }} @@ -67,71 +65,15 @@ jobs: path: target ref: ${{ matrix.branches }} - - name: Copy all workflow templates - run: | - echo 'SUMMARY<> $GITHUB_ENV - draft_only=0 - for workflow in ./source/workflow-templates/*.yml; do - echo "❓ Looking for $workflow" - if [ -f "$workflow" ]; then - filename=$(basename "$workflow") - target_file="./target/.github/workflows/$filename" - - # Only copy if the file exists in the target repository - if [ -f "$target_file" ]; then - if [ -f "./target/.github/actions-lock.txt" ]; then - locked_version=$(grep " $filename" ./target/.github/actions-lock.txt | cat) - else - echo "# SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors" >> ./target/.github/actions-lock.txt - echo "# SPDX-License""-Identifier: MIT" >> ./target/.github/actions-lock.txt - locked_version="" - fi - locked_version=$(echo $locked_version | cut -f 1 -d " ") - new_version=$(md5sum $workflow | cut -f 1 -d " ") - - # Only update if the action changes - if [[ "$locked_version" != "$new_version" ]]; then - echo "ℹ️ Locked version: $locked_version" - echo "ℹ️ Current version: $new_version" - echo "🆙 Updating existing workflow: $filename" - echo "- 🆙 Updated [$filename](https://github.com/LibreCodeCoop/.github/commits/main/workflow-templates/$filename)" >> $GITHUB_ENV - - cp "$workflow" "$target_file" - - # Apply patch if one exists - if [ -f "$target_file.patch" ]; then - echo "🩹 Applying patch" - cd ./target - set +e - patch -p1 < ".github/workflows/$filename.patch" - patch_worked=$? - set -e - cd - - if [[ "$patch_worked" == "0" ]]; then - echo " - Patch applied" >> $GITHUB_ENV - else - echo " - [ ] ❌ Patch failed" >> $GITHUB_ENV - draft_only=1 - fi - fi - - if [[ "$locked_version" != "" ]]; then - sed -i "s/$locked_version $filename/$new_version $filename/" ./target/.github/actions-lock.txt - else - echo "$new_version $filename" >> ./target/.github/actions-lock.txt - fi - else - echo "✅ Skipping $filename: already up to date" - fi - else - echo "⏭️ Skipping $filename: does not exist in target repository" - fi - fi - done - echo 'EOF' >> $GITHUB_ENV - echo "DRAFT_ONLY=${draft_only}" >> $GITHUB_ENV + - name: Synchronize workflow templates + id: sync + uses: LibreCodeCoop/github-workflows/actions/sync-workflows@57e644fe4882e942ac19bbe99729b4b7e3c9014e + with: + source: source/workflow-templates + target: target - name: Create Pull Request + if: ${{ steps.sync.outputs.changed == 'true' }} uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 with: token: ${{ steps.app-token.outputs.token }} @@ -142,11 +84,11 @@ jobs: signoff: true branch: 'automated/noid/${{ matrix.branches }}-update-workflows' title: '[${{ matrix.branches }}] ci(actions): Update workflow templates from organization template repository' - draft: ${{ env.DRAFT_ONLY == 1 }} + draft: ${{ steps.sync.outputs.patch_failed == 'true' }} add-paths: .github/workflows/*.yml,.github/actions-lock.txt body: | Automated update of all workflow templates from [LibreCodeCoop/.github](https://github.com/LibreCodeCoop/.github) - ${{ env.SUMMARY }} + ${{ steps.sync.outputs.summary }} labels: | dependencies 3. to review From a55cdd73847486baf22087f1436db25f1c4b84c0 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sun, 20 Sep 2026 18:23:28 -0300 Subject: [PATCH 5/5] ci: keep Extract stable branches in local patch Signed-off-by: Vitor Mattos --- .github/workflows/sync-workflow-templates.yml.patch | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/.github/workflows/sync-workflow-templates.yml.patch b/.github/workflows/sync-workflow-templates.yml.patch index 7a0da26..a90c064 100644 --- a/.github/workflows/sync-workflow-templates.yml.patch +++ b/.github/workflows/sync-workflow-templates.yml.patch @@ -1,12 +1,10 @@ ---- .github/workflows/sync-workflow-templates.yml -+++ .github/workflows/sync-workflow-templates.yml -@@ -28,9 +28,8 @@ +diff --git a/.github/workflows/sync-workflow-templates.yml b/.github/workflows/sync-workflow-templates.yml +--- a/.github/workflows/sync-workflow-templates.yml ++++ b/.github/workflows/sync-workflow-templates.yml +@@ -26,6 +26,8 @@ jobs: matrix: branches: - ${{ github.event.repository.default_branch }} -- - 'stable35' -- - 'stable34' -- - 'stable33' + - 'stable32' + - 'stable31'