|
20 | 20 | contents: write |
21 | 21 | pull-requests: write |
22 | 22 | steps: |
| 23 | + - name: Validate GitHub App configuration |
| 24 | + env: |
| 25 | + WORKFLOW_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} |
| 26 | + WORKFLOW_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} |
| 27 | + run: | |
| 28 | + if [ -z "$WORKFLOW_APP_ID" ]; then |
| 29 | + echo "::error::LIBRECODE_WORKFLOW_APP_ID is not configured." |
| 30 | + exit 1 |
| 31 | + fi |
| 32 | + if [ -z "$WORKFLOW_APP_PRIVATE_KEY" ]; then |
| 33 | + echo "::error::LIBRECODE_WORKFLOW_APP_PRIVATE_KEY is not configured." |
| 34 | + exit 1 |
| 35 | + fi |
| 36 | +
|
| 37 | + - name: Create GitHub App token |
| 38 | + id: app-token |
| 39 | + uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 |
| 40 | + with: |
| 41 | + app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} |
| 42 | + private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} |
| 43 | + owner: LibreCodeCoop |
| 44 | + repositories: github-workflows |
| 45 | + permission-contents: write |
| 46 | + permission-pull-requests: write |
| 47 | + permission-workflows: write |
| 48 | + |
23 | 49 | - name: Checkout |
24 | 50 | uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
25 | 51 | with: |
|
57 | 83 | if: steps.refresh.outcome == 'success' |
58 | 84 | uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 |
59 | 85 | with: |
60 | | - token: ${{ secrets.WORKFLOW_UPDATE_TOKEN }} |
| 86 | + token: ${{ steps.app-token.outputs.token }} |
61 | 87 | commit-message: 'chore: refresh upstream workflow pins' |
62 | 88 | committer: GitHub <noreply@github.com> |
63 | 89 | author: github-workflows bot <noreply@github.com> |
|
72 | 98 | upstream/sources.json |
73 | 99 | upstream/vendor/** |
74 | 100 | workflow-templates/** |
| 101 | + .github/workflows/** |
75 | 102 |
|
76 | 103 | - name: Fail when patches need manual updates |
77 | 104 | if: steps.render.outcome == 'failure' |
|
0 commit comments