From abc4de013668ea30cd296db03ceb7406733dad73 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:08:10 -0300 Subject: [PATCH 01/11] ci: materialize organization workflow catalog --- .github/workflows/psalm.yml | 59 ++++++++++++++++++++++++++++++++----- 1 file changed, 52 insertions(+), 7 deletions(-) diff --git a/.github/workflows/psalm.yml b/.github/workflows/psalm.yml index b7fa510..33dfdec 100644 --- a/.github/workflows/psalm.yml +++ b/.github/workflows/psalm.yml @@ -1,16 +1,61 @@ -# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors -# SPDX-License-Identifier: AGPL-3.0-or-later - -# This workflow is published through the LibreCode organization catalog. -# Implementation: LibreCodeCoop/github-workflows +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2022-2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-License-Identifier: MIT name: Static analysis on: pull_request +concurrency: + group: psalm-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + permissions: contents: read jobs: - psalm: - uses: LibreCodeCoop/github-workflows/.github/workflows/psalm.yml@bedd8421ad6c95914f10f0dc631333223d17c515 + static-analysis: + runs-on: ubuntu-latest + + name: static-psalm-analysis + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Get php version + id: versions + uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3 + + - name: Check enforcement of minimum PHP version ${{ steps.versions.outputs.php-min }} in psalm.xml + run: grep 'phpVersion="${{ steps.versions.outputs.php-min }}' psalm.xml + + - name: Set up php${{ steps.versions.outputs.php-available }} + uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2 + with: + php-version: ${{ steps.versions.outputs.php-available }} + extensions: bz2, ctype, curl, dom, fileinfo, gd, iconv, intl, json, libxml, mbstring, openssl, pcntl, posix, session, simplexml, xmlreader, xmlwriter, zip, zlib, sqlite, pdo_sqlite + coverage: none + ini-file: development + # Temporary workaround for missing pcntl_* in PHP 8.3 + ini-values: disable_functions= + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + + - name: Remove nextcloud/ocp + run: | + composer remove nextcloud/ocp --dev --no-scripts + + - name: Install composer dependencies + uses: ramsey/composer-install@65e4f84970763564f46a70b8a54b90d033b3bdda # 4.0.0 + + - name: Install nextcloud/ocp:dev-${{ steps.versions.outputs.branches-max }} + run: composer require --dev nextcloud/ocp:dev-${{ steps.versions.outputs.branches-max }} --ignore-platform-reqs --with-dependencies + + - name: Run coding standards check + run: composer run psalm -- --threads=1 --monochrome --no-progress --output-format=github From abd29485fbb99a379af44e98afe19f72ec6c1d05 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:08:14 -0300 Subject: [PATCH 02/11] ci: materialize organization workflow catalog --- .github/workflows/reuse.yml | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/.github/workflows/reuse.yml b/.github/workflows/reuse.yml index e652788..3edce05 100644 --- a/.github/workflows/reuse.yml +++ b/.github/workflows/reuse.yml @@ -1,8 +1,6 @@ -# This workflow is maintained by LibreCodeCoop/github-workflows and published -# through the LibreCodeCoop organization workflow catalog. -# Managed by LibreCode workflow synchronization; local edits are treated as divergence. +# This workflow is provided via the organization template repository # -# https://github.com/LibreCodeCoop/github-workflows +# https://github.com/LibreCodeCoop/.github # https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization # SPDX-FileCopyrightText: 2022 Free Software Foundation Europe e.V. From b6a72a5a878e528f46097a5e9d94f2aefb9941ba Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:08:18 -0300 Subject: [PATCH 03/11] ci: materialize organization workflow catalog --- .github/workflows/openapi.yml | 92 ++++++++++++++++++++++++++++++++--- 1 file changed, 86 insertions(+), 6 deletions(-) diff --git a/.github/workflows/openapi.yml b/.github/workflows/openapi.yml index fa6fdde..a752d09 100644 --- a/.github/workflows/openapi.yml +++ b/.github/workflows/openapi.yml @@ -1,8 +1,11 @@ -# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors -# SPDX-License-Identifier: AGPL-3.0-or-later - -# This workflow is published through the LibreCode organization catalog. -# Implementation: LibreCodeCoop/github-workflows +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-FileCopyrightText: 2024 Arthur Schiwon +# SPDX-License-Identifier: MIT name: OpenAPI @@ -11,6 +14,83 @@ on: pull_request permissions: contents: read +concurrency: + group: openapi-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + jobs: openapi: - uses: LibreCodeCoop/github-workflows/.github/workflows/openapi.yml@bfd8f06a82ff2fdd95becc1f752363c640f314ca + runs-on: ubuntu-latest + + if: ${{ github.repository_owner != 'nextcloud-gmbh' }} + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Get php version + id: php_versions + uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3 + + - name: Set up php + uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2 + with: + php-version: ${{ steps.php_versions.outputs.php-available }} + extensions: xml + coverage: none + ini-file: development + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + + - name: Check Typescript OpenApi types + id: check_typescript_openapi + uses: andstor/file-existence-action@558493d6c74bf472d87c84eab196434afc2fa029 # v3.1.0 + with: + files: "src/types/openapi/openapi*.ts" + + - name: Read package.json node and npm engines version + if: steps.check_typescript_openapi.outputs.files_exists == 'true' + uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3 + id: node_versions + # Continue if no package.json + continue-on-error: true + with: + fallbackNode: '^24' + fallbackNpm: '^11.3' + + - name: Set up node ${{ steps.node_versions.outputs.nodeVersion }} + if: ${{ steps.node_versions.outputs.nodeVersion }} + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: ${{ steps.node_versions.outputs.nodeVersion }} + + - name: Set up npm ${{ steps.node_versions.outputs.npmVersion }} + if: ${{ steps.node_versions.outputs.nodeVersion }} + run: npm i -g 'npm@${{ steps.node_versions.outputs.npmVersion }}' + + - name: Install dependencies + if: ${{ steps.node_versions.outputs.nodeVersion }} + env: + CYPRESS_INSTALL_BINARY: 0 + PUPPETEER_SKIP_DOWNLOAD: true + run: | + npm ci + + - name: Install composer dependencies + uses: ramsey/composer-install@65e4f84970763564f46a70b8a54b90d033b3bdda # 4.0.0 + + - name: Regenerate OpenAPI + run: composer run openapi + + - name: Check openapi*.json and typescript changes + run: | + bash -c "[[ ! \"`git status --porcelain `\" ]] || (echo 'Please run \"composer run openapi\" and commit the openapi*.json files and (if applicable) src/types/openapi/openapi*.ts, see the section \"Show changes on failure\" for details' && exit 1)" + + - name: Show changes on failure + if: failure() + run: | + git status + git --no-pager diff + exit 1 # make it red to grab attention From c52c28c7ff5838f1a11a13c32852420556330b8b Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:08:21 -0300 Subject: [PATCH 04/11] ci: materialize organization workflow catalog --- .github/workflows/lint-php.yml | 74 ++++++++++++++++++++++++++++++---- 1 file changed, 67 insertions(+), 7 deletions(-) diff --git a/.github/workflows/lint-php.yml b/.github/workflows/lint-php.yml index a54876f..be01aab 100644 --- a/.github/workflows/lint-php.yml +++ b/.github/workflows/lint-php.yml @@ -1,8 +1,10 @@ -# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors -# SPDX-License-Identifier: AGPL-3.0-or-later - -# This workflow is published through the LibreCode organization catalog. -# Implementation: LibreCodeCoop/github-workflows +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2021-2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-License-Identifier: MIT name: Lint php @@ -11,6 +13,64 @@ on: pull_request permissions: contents: read +concurrency: + group: lint-php-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + jobs: - lint-php: - uses: LibreCodeCoop/github-workflows/.github/workflows/lint-php.yml@bc97b54e3d33d58d6075a0994883acde00f0556c + matrix: + runs-on: ubuntu-latest + outputs: + php-min: ${{ steps.versions.outputs.php-min }} + php-max: ${{ steps.versions.outputs.php-max }} + steps: + - name: Checkout app + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Get version matrix + id: versions + uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3 + + php-lint: + runs-on: ubuntu-latest + needs: matrix + strategy: + matrix: + php-versions: ['${{ needs.matrix.outputs.php-min }}', '${{ needs.matrix.outputs.php-max }}'] + + name: php-lint + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Set up php ${{ matrix.php-versions }} + uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2 + with: + php-version: ${{ matrix.php-versions }} + extensions: bz2, ctype, curl, dom, fileinfo, gd, iconv, intl, json, libxml, mbstring, openssl, pcntl, posix, session, simplexml, xmlreader, xmlwriter, zip, zlib, sqlite, pdo_sqlite + coverage: none + ini-file: development + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + + - name: Lint + run: composer run lint + + summary: + permissions: + contents: none + runs-on: ubuntu-latest + needs: php-lint + + if: always() + + name: php-lint-summary + + steps: + - name: Summary status + run: if ${{ needs.php-lint.result != 'success' && needs.php-lint.result != 'skipped' }}; then exit 1; fi From 60c4199cdfafefd31a33a4454d2b7d3f9cff2281 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:08:26 -0300 Subject: [PATCH 05/11] ci: materialize organization workflow catalog --- .github/workflows/npm-build.yml | 112 +++++++++++++++++++++++++++++--- 1 file changed, 104 insertions(+), 8 deletions(-) diff --git a/.github/workflows/npm-build.yml b/.github/workflows/npm-build.yml index fd95cf0..7aeabe8 100644 --- a/.github/workflows/npm-build.yml +++ b/.github/workflows/npm-build.yml @@ -1,8 +1,10 @@ -# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors -# SPDX-License-Identifier: AGPL-3.0-or-later - -# This workflow is published through the LibreCode organization catalog. -# Implementation: LibreCodeCoop/github-workflows +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2021-2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-License-Identifier: MIT name: Build Javascript @@ -10,8 +12,102 @@ on: pull_request permissions: contents: read - pull-requests: read + +concurrency: + group: node-${{ github.head_ref || github.run_id }} + cancel-in-progress: true jobs: - npm-build: - uses: LibreCodeCoop/github-workflows/.github/workflows/npm-build.yml@d96f4b5dcf780dea20d8843f54c4b52207dc25fd + changes: + runs-on: ubuntu-latest + permissions: + contents: read + pull-requests: read + + outputs: + src: ${{ steps.changes.outputs.src}} + + steps: + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 + id: changes + continue-on-error: true + with: + filters: | + src: + - '.github/workflows/**' + - 'src/**' + - 'appinfo/info.xml' + - 'package.json' + - 'package-lock.json' + - 'tsconfig.json' + - '**.js' + - '**.ts' + - '**.vue' + + build: + runs-on: ubuntu-latest + + needs: changes + if: needs.changes.outputs.src != 'false' + + name: NPM build + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Read package.json node and npm engines version + uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3 + id: versions + with: + fallbackNode: '^24' + fallbackNpm: '^11.3' + + - name: Set up node ${{ steps.versions.outputs.nodeVersion }} + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: ${{ steps.versions.outputs.nodeVersion }} + + - name: Set up npm ${{ steps.versions.outputs.npmVersion }} + run: npm i -g 'npm@${{ steps.versions.outputs.npmVersion }}' + + - name: Validate package-lock.json # See https://github.com/npm/cli/issues/4460 + run: | + npm i -g npm-package-lock-add-resolved@1.1.4 + npm-package-lock-add-resolved + git --no-pager diff --exit-code + + - name: Install dependencies & build + env: + CYPRESS_INSTALL_BINARY: 0 + PUPPETEER_SKIP_DOWNLOAD: true + run: | + npm ci + npm run build --if-present + + - name: Check build changes + run: | + bash -c "[[ ! \"`git status --porcelain `\" ]] || (echo 'Please recompile and commit the assets, see the section \"Show changes on failure\" for details' && exit 1)" + + - name: Show changes on failure + if: failure() + run: | + git status + git --no-pager diff + exit 1 # make it red to grab attention + + summary: + permissions: + contents: none + runs-on: ubuntu-latest + needs: [changes, build] + + if: always() + + # This is the summary, we just avoid to rename it so that branch protection rules still match + name: node + + steps: + - name: Summary status + run: if ${{ needs.changes.outputs.src != 'false' && needs.build.result != 'success' }}; then exit 1; fi From 29daf3e9a1011d57a84475614d3f28fca3b2b488 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:08:29 -0300 Subject: [PATCH 06/11] ci: materialize organization workflow catalog --- .github/workflows/lint-php-cs.yml | 52 ++++++++++++++++++++++++++----- 1 file changed, 45 insertions(+), 7 deletions(-) diff --git a/.github/workflows/lint-php-cs.yml b/.github/workflows/lint-php-cs.yml index 04b650d..fc9867e 100644 --- a/.github/workflows/lint-php-cs.yml +++ b/.github/workflows/lint-php-cs.yml @@ -1,8 +1,10 @@ -# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors -# SPDX-License-Identifier: AGPL-3.0-or-later - -# This workflow is published through the LibreCode organization catalog. -# Implementation: LibreCodeCoop/github-workflows +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2021-2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-License-Identifier: MIT name: Lint php-cs @@ -11,6 +13,42 @@ on: pull_request permissions: contents: read +concurrency: + group: lint-php-cs-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + jobs: - lint-php-cs: - uses: LibreCodeCoop/github-workflows/.github/workflows/lint-php-cs.yml@bc97b54e3d33d58d6075a0994883acde00f0556c + lint: + runs-on: ubuntu-latest + + name: php-cs + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Get php version + id: versions + uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3 + + - name: Set up php${{ steps.versions.outputs.php-min }} + uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2 + with: + php-version: ${{ steps.versions.outputs.php-min }} + extensions: bz2, ctype, curl, dom, fileinfo, gd, iconv, intl, json, libxml, mbstring, openssl, pcntl, posix, session, simplexml, xmlreader, xmlwriter, zip, zlib, sqlite, pdo_sqlite + coverage: none + ini-file: development + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + + - name: Remove nextcloud/ocp + run: | + composer remove nextcloud/ocp --dev --no-scripts + + - name: Install composer dependencies + uses: ramsey/composer-install@65e4f84970763564f46a70b8a54b90d033b3bdda # 4.0.0 + + - name: Lint + run: composer run cs:check || ( echo 'Please run `composer run cs:fix` to format your code' && exit 1 ) From c447af456b7363c77aeb257b5af1732977e60456 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:09:42 -0300 Subject: [PATCH 07/11] ci: materialize organization workflow catalog --- .github/workflows/lint-eslint.yml | 99 ++++++++++++++++++++++++++++--- 1 file changed, 91 insertions(+), 8 deletions(-) diff --git a/.github/workflows/lint-eslint.yml b/.github/workflows/lint-eslint.yml index 6bf3e9c..8614833 100644 --- a/.github/workflows/lint-eslint.yml +++ b/.github/workflows/lint-eslint.yml @@ -1,8 +1,10 @@ -# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors -# SPDX-License-Identifier: AGPL-3.0-or-later - -# This workflow is published through the LibreCode organization catalog. -# Implementation: LibreCodeCoop/github-workflows +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2021-2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-License-Identifier: MIT name: Lint eslint @@ -10,8 +12,89 @@ on: pull_request permissions: contents: read - pull-requests: read + +concurrency: + group: lint-eslint-${{ github.head_ref || github.run_id }} + cancel-in-progress: true jobs: - eslint: - uses: LibreCodeCoop/github-workflows/.github/workflows/lint-eslint.yml@bf6d298f17eacdada7d2f771cad8fe29a11ec09e + changes: + runs-on: ubuntu-latest + permissions: + contents: read + pull-requests: read + + outputs: + src: ${{ steps.changes.outputs.src}} + + steps: + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 + id: changes + continue-on-error: true + with: + filters: | + src: + - '.github/workflows/**' + - 'src/**' + - 'appinfo/info.xml' + - 'package.json' + - 'package-lock.json' + - 'tsconfig.json' + - '.eslintrc.*' + - '.eslintignore' + - '**.js' + - '**.ts' + - '**.vue' + + lint: + runs-on: ubuntu-latest + + needs: changes + if: needs.changes.outputs.src != 'false' + + name: NPM lint + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Read package.json node and npm engines version + uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3 + id: versions + with: + fallbackNode: '^24' + fallbackNpm: '^11.3' + + - name: Set up node ${{ steps.versions.outputs.nodeVersion }} + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: ${{ steps.versions.outputs.nodeVersion }} + + - name: Set up npm ${{ steps.versions.outputs.npmVersion }} + run: npm i -g 'npm@${{ steps.versions.outputs.npmVersion }}' + + - name: Install dependencies + env: + CYPRESS_INSTALL_BINARY: 0 + PUPPETEER_SKIP_DOWNLOAD: true + run: npm ci + + - name: Lint + run: npm run lint + + summary: + permissions: + contents: none + runs-on: ubuntu-latest + needs: [changes, lint] + + if: always() + + # This is the summary, we just avoid to rename it so that branch protection rules still match + name: eslint + + steps: + - name: Summary status + run: if ${{ needs.changes.outputs.src != 'false' && needs.lint.result != 'success' }}; then exit 1; fi From 05eb511c436d75720a901bf7abc5d95bd5fb6fbe Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:09:45 -0300 Subject: [PATCH 08/11] ci: materialize organization workflow catalog --- .github/workflows/lint-info-xml.yml | 38 +++++++++++++++++++++++------ 1 file changed, 31 insertions(+), 7 deletions(-) diff --git a/.github/workflows/lint-info-xml.yml b/.github/workflows/lint-info-xml.yml index e0372e1..a02c24f 100644 --- a/.github/workflows/lint-info-xml.yml +++ b/.github/workflows/lint-info-xml.yml @@ -1,8 +1,10 @@ -# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors -# SPDX-License-Identifier: AGPL-3.0-or-later - -# This workflow is published through the LibreCode organization catalog. -# Implementation: LibreCodeCoop/github-workflows +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2021-2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-License-Identifier: MIT name: Lint info.xml @@ -11,6 +13,28 @@ on: pull_request permissions: contents: read +concurrency: + group: lint-info-xml-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + jobs: - lint-info-xml: - uses: LibreCodeCoop/github-workflows/.github/workflows/lint-info-xml.yml@c5f578281fa7d270b839866ebc07047287ff50d8 + xml-linters: + runs-on: ubuntu-latest + + name: info.xml lint + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + sparse-checkout: | + appinfo/ + + - name: Download schema + run: wget https://raw.githubusercontent.com/nextcloud/appstore/master/nextcloudappstore/api/v1/release/info.xsd + + - name: Lint info.xml + uses: ChristophWurst/xmllint-action@36f2a302f84f8c83fceea0b9c59e1eb4a616d3c1 # v1.2 + with: + xml-file: ./appinfo/info.xml + xml-schema-file: ./info.xsd From 07cdd8a71408ea6d405dc076aa28cbe57d17a5c0 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:09:50 -0300 Subject: [PATCH 09/11] ci: materialize organization workflow catalog --- .github/workflows/lint-stylelint.yml | 51 ++++++++++++++++++++++++---- 1 file changed, 44 insertions(+), 7 deletions(-) diff --git a/.github/workflows/lint-stylelint.yml b/.github/workflows/lint-stylelint.yml index 836b1dc..7b61a7e 100644 --- a/.github/workflows/lint-stylelint.yml +++ b/.github/workflows/lint-stylelint.yml @@ -1,8 +1,10 @@ -# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors -# SPDX-License-Identifier: AGPL-3.0-or-later - -# This workflow is published through the LibreCode organization catalog. -# Implementation: LibreCodeCoop/github-workflows +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2021-2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-License-Identifier: MIT name: Lint stylelint @@ -11,6 +13,41 @@ on: pull_request permissions: contents: read +concurrency: + group: lint-stylelint-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + jobs: - stylelint: - uses: LibreCodeCoop/github-workflows/.github/workflows/lint-stylelint.yml@bf6d298f17eacdada7d2f771cad8fe29a11ec09e + lint: + runs-on: ubuntu-latest + + name: stylelint + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Read package.json node and npm engines version + uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3 + id: versions + with: + fallbackNode: '^24' + fallbackNpm: '^11.3' + + - name: Set up node ${{ steps.versions.outputs.nodeVersion }} + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: ${{ steps.versions.outputs.nodeVersion }} + + - name: Set up npm ${{ steps.versions.outputs.npmVersion }} + run: npm i -g 'npm@${{ steps.versions.outputs.npmVersion }}' + + - name: Install dependencies + env: + CYPRESS_INSTALL_BINARY: 0 + run: npm ci + + - name: Lint + run: npm run stylelint From d0fa82722d84523486e7c38dea8a084f15568e65 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:09:54 -0300 Subject: [PATCH 10/11] ci: materialize organization workflow catalog --- .../block-unconventional-commits.yml | 32 +++++++++++++++---- 1 file changed, 25 insertions(+), 7 deletions(-) diff --git a/.github/workflows/block-unconventional-commits.yml b/.github/workflows/block-unconventional-commits.yml index 5c60dd3..cdcb2f2 100644 --- a/.github/workflows/block-unconventional-commits.yml +++ b/.github/workflows/block-unconventional-commits.yml @@ -1,8 +1,10 @@ -# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors -# SPDX-License-Identifier: AGPL-3.0-or-later - -# This workflow is published through the LibreCode organization catalog. -# Implementation: LibreCodeCoop/github-workflows +# This workflow is provided via the organization template repository +# +# https://github.com/LibreCodeCoop/.github +# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization +# +# SPDX-FileCopyrightText: 2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-License-Identifier: MIT name: Block unconventional commits @@ -13,6 +15,22 @@ on: permissions: contents: read +concurrency: + group: block-unconventional-commits-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + jobs: - conventional-commits: - uses: LibreCodeCoop/github-workflows/.github/workflows/block-unconventional-commits.yml@e2878c8c2d12d0d323116dedd2bcff37706a7eba + block-unconventional-commits: + name: Block unconventional commits + + runs-on: ubuntu-latest + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - uses: webiny/action-conventional-commits@7f91b1595ca1951cdb671ddc9f07a49081ec5b69 # v1.4.2 + with: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} From 84899900d2a71a09eebdc03fdbcdcaa6e9217f9c Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Thu, 24 Sep 2026 00:09:58 -0300 Subject: [PATCH 11/11] ci: materialize organization workflow catalog --- .github/workflows/sync-workflow-templates.yml | 111 ++++++++++++++++-- 1 file changed, 101 insertions(+), 10 deletions(-) diff --git a/.github/workflows/sync-workflow-templates.yml b/.github/workflows/sync-workflow-templates.yml index d6fbc8e..d7aacf2 100644 --- a/.github/workflows/sync-workflow-templates.yml +++ b/.github/workflows/sync-workflow-templates.yml @@ -6,8 +6,11 @@ # SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors # SPDX-License-Identifier: MIT -# This workflow will update all workflow templates -# Additionally it will reapply `workflow.yml.patch` files after syncing and only then commit the result +# This workflow will update all workflow templates. +# Additionally it will reapply workflow.yml.patch files after syncing and only then commit the result. +# +# Authentication is selected explicitly with vars.WORKFLOW_SYNC_AUTH_MODE. +# See docs/cross-repository-automation.md for modes, credentials and GITHUB_TOKEN limitations. name: Update workflows on: workflow_dispatch: @@ -39,18 +42,99 @@ jobs: with: require: admin - - name: Create GitHub App token - id: app-token - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + - name: Validate workflow sync authentication + shell: bash + env: + AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }} + LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + LIBRECODE_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} + CONSUMER_APP_ID: ${{ vars.WORKFLOW_SYNC_APP_ID }} + CONSUMER_APP_PRIVATE_KEY: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }} + CONSUMER_TOKEN: ${{ secrets.WORKFLOW_SYNC_TOKEN }} + run: | + set -euo pipefail + + case "${AUTH_MODE}" in + librecode-app) + [[ -n "${LIBRECODE_APP_ID}" && -n "${LIBRECODE_APP_PRIVATE_KEY}" ]] || { + echo "::error::librecode-app requires LIBRECODE_WORKFLOW_APP_ID and LIBRECODE_WORKFLOW_APP_PRIVATE_KEY" + exit 1 + } + ;; + github-app) + [[ -n "${CONSUMER_APP_ID}" && -n "${CONSUMER_APP_PRIVATE_KEY}" ]] || { + echo "::error::github-app requires WORKFLOW_SYNC_APP_ID and WORKFLOW_SYNC_APP_PRIVATE_KEY" + exit 1 + } + ;; + token) + [[ -n "${CONSUMER_TOKEN}" ]] || { + echo "::error::token mode requires WORKFLOW_SYNC_TOKEN" + exit 1 + } + ;; + github-token) + ;; + *) + echo "::error::Unsupported WORKFLOW_SYNC_AUTH_MODE: ${AUTH_MODE}" + exit 1 + ;; + esac + + - name: Create LibreCode GitHub App token + if: ${{ vars.WORKFLOW_SYNC_AUTH_MODE == '' || vars.WORKFLOW_SYNC_AUTH_MODE == 'librecode-app' }} + id: librecode-app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} - owner: LibreCodeCoop + owner: ${{ github.repository_owner }} + repositories: ${{ github.event.repository.name }} + permission-contents: write + permission-pull-requests: write + permission-workflows: write + + - name: Create consumer GitHub App token + if: ${{ vars.WORKFLOW_SYNC_AUTH_MODE == 'github-app' }} + id: consumer-app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 + with: + app-id: ${{ vars.WORKFLOW_SYNC_APP_ID }} + private-key: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }} + owner: ${{ github.repository_owner }} repositories: ${{ github.event.repository.name }} permission-contents: write permission-pull-requests: write permission-workflows: write + - name: Resolve workflow sync token + id: auth-token + shell: bash + env: + AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }} + LIBRECODE_APP_TOKEN: ${{ steps.librecode-app-token.outputs.token }} + CONSUMER_APP_TOKEN: ${{ steps.consumer-app-token.outputs.token }} + CONSUMER_TOKEN: ${{ secrets.WORKFLOW_SYNC_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + set -euo pipefail + + case "${AUTH_MODE}" in + librecode-app) token="${LIBRECODE_APP_TOKEN}" ;; + github-app) token="${CONSUMER_APP_TOKEN}" ;; + token) token="${CONSUMER_TOKEN}" ;; + github-token) token="${GITHUB_TOKEN}" ;; + *) exit 1 ;; + esac + + [[ -n "${token}" ]] || { + echo "::error::Selected workflow sync authentication produced an empty token" + exit 1 + } + + echo "::add-mask::${token}" + echo "token=${token}" >> "${GITHUB_OUTPUT}" + - name: Checkout workflow repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -58,6 +142,12 @@ jobs: path: source repository: LibreCodeCoop/.github + - name: Record workflow catalog revision + id: catalog-revision + working-directory: source + shell: bash + run: echo "sha=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT" + - name: Checkout app uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -67,19 +157,20 @@ jobs: - name: Synchronize workflow templates id: sync - uses: LibreCodeCoop/github-workflows/actions/sync-workflows@57e644fe4882e942ac19bbe99729b4b7e3c9014e + uses: LibreCodeCoop/.github/actions/sync-workflows@492e6c7c5a9bb7642f39238583003d2cb93f3ba6 # organization helpers with: source: source/workflow-templates target: target + catalog-commit: ${{ steps.catalog-revision.outputs.sha }} - name: Create Pull Request if: ${{ steps.sync.outputs.changed == 'true' }} uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 with: - token: ${{ steps.app-token.outputs.token }} + token: ${{ steps.auth-token.outputs.token }} commit-message: 'ci(actions): Update workflow templates from organization template repository' committer: GitHub - author: librecode-workflow-automation[bot] <331658022+librecode-workflow-automation[bot]@users.noreply.github.com> + author: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> path: target signoff: true branch: 'automated/noid/${{ matrix.branches }}-update-workflows' @@ -87,7 +178,7 @@ jobs: draft: ${{ steps.sync.outputs.patch_failed == 'true' }} add-paths: .github/workflows/*.yml,.github/actions-lock.txt body: | - Automated update of all workflow templates from [LibreCodeCoop/.github](https://github.com/LibreCodeCoop/.github) + Automated update of workflow templates from [LibreCodeCoop/.github](https://github.com/LibreCodeCoop/.github) ${{ steps.sync.outputs.summary }} labels: | dependencies