Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions patches/nextcloud/sync-workflow-templates.yml.patch
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@
+ shell: bash
+ env:
+ AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }}
+ LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
+ LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
+ LIBRECODE_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}
+ CONSUMER_APP_ID: ${{ vars.WORKFLOW_SYNC_APP_ID }}
+ CONSUMER_APP_PRIVATE_KEY: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }}
Expand Down Expand Up @@ -78,7 +78,7 @@
+ id: librecode-app-token
+ uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4
+ with:
+ app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
+ app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
+ private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}
+ owner: ${{ github.repository_owner }}
+ repositories: ${{ github.event.repository.name }}
Expand Down
7 changes: 7 additions & 0 deletions tests/test_portable_workflow_sync_auth.py
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,13 @@ def test_external_modes_do_not_require_librecode_credentials(self) -> None:
self.assertIn('github-app) token="${CONSUMER_APP_TOKEN}"', content)
self.assertIn('token) token="${CONSUMER_TOKEN}"', content)

def test_librecode_app_credentials_use_actions_secrets(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")

self.assertIn("LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}", content)
self.assertIn("app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}", content)
self.assertNotIn("vars.LIBRECODE_WORKFLOW_APP_ID", content)

def test_generated_pull_request_uses_selected_token(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")

Expand Down
15 changes: 11 additions & 4 deletions tests/test_prepare_release_template.py
Original file line number Diff line number Diff line change
Expand Up @@ -43,21 +43,28 @@ def test_dispatch_help_is_concise_and_explains_risky_inputs(self) -> None:

def test_template_delegates_all_release_stages_to_versioned_actions(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")
sha = "622599cc128ec55007b443d2908f78da930b8a21"
sha = "5a16fb0ae5b846117f70e1d86a1d25e46492c333"

self.assertIn(
f"actions/release-prepare@{sha} # v0.5.0",
f"actions/release-prepare@{sha} # v0.6.2",
content,
)
self.assertIn(
f"actions/release-post-merge@{sha} # v0.5.0",
f"actions/release-post-merge@{sha} # v0.6.2",
content,
)
self.assertIn(
f"actions/release-publication@{sha} # v0.5.0",
f"actions/release-publication@{sha} # v0.6.2",
content,
)

def test_release_mutation_credentials_use_actions_secrets(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")

self.assertEqual(2, content.count("secrets.LIBRECODE_WORKFLOW_APP_ID"))
self.assertEqual(2, content.count("secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY"))
self.assertNotIn("vars.LIBRECODE_WORKFLOW_APP_ID", content)

def test_template_keeps_permissions_stage_scoped(self) -> None:
content = TEMPLATE.read_text(encoding="utf-8")

Expand Down
10 changes: 5 additions & 5 deletions workflow-templates/prepare-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ jobs:
ref: ${{ inputs.ref != '' && inputs.ref || inputs.branch }}

- name: Prepare release
uses: LibreCodeCoop/github-workflows/actions/release-prepare@622599cc128ec55007b443d2908f78da930b8a21 # v0.5.0
uses: LibreCodeCoop/github-workflows/actions/release-prepare@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2
with:
branch: ${{ inputs.branch }}
ref: ${{ inputs.ref }}
Expand All @@ -93,7 +93,7 @@ jobs:
config-path: .nextcloud-release.yml
actor: ${{ github.actor }}
github-token: ${{ secrets.GITHUB_TOKEN }}
app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
app-private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}

post_merge:
Expand All @@ -118,14 +118,14 @@ jobs:
ref: ${{ github.event.pull_request.base.ref }}

- name: Finalize merged release
uses: LibreCodeCoop/github-workflows/actions/release-post-merge@622599cc128ec55007b443d2908f78da930b8a21 # v0.5.0
uses: LibreCodeCoop/github-workflows/actions/release-post-merge@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2
with:
pull-request-number: ${{ github.event.pull_request.number }}
merger: ${{ github.event.pull_request.merged_by.login }}
config-path: .nextcloud-release.yml
prepare-workflow-path: .github/workflows/prepare-release.yml
github-token: ${{ secrets.GITHUB_TOKEN }}
app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
app-private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}

verify_publication:
Expand All @@ -145,7 +145,7 @@ jobs:
ref: ${{ github.event.release.tag_name }}

- name: Verify publication
uses: LibreCodeCoop/github-workflows/actions/release-publication@622599cc128ec55007b443d2908f78da930b8a21 # v0.5.0
uses: LibreCodeCoop/github-workflows/actions/release-publication@5a16fb0ae5b846117f70e1d86a1d25e46492c333 # v0.6.2
with:
github-release-id: ${{ github.event.release.id }}
config-path: .nextcloud-release.yml
Expand Down
4 changes: 2 additions & 2 deletions workflow-templates/sync-workflow-templates.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ jobs:
shell: bash
env:
AUTH_MODE: ${{ vars.WORKFLOW_SYNC_AUTH_MODE || 'librecode-app' }}
LIBRECODE_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
LIBRECODE_APP_ID: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
LIBRECODE_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}
CONSUMER_APP_ID: ${{ vars.WORKFLOW_SYNC_APP_ID }}
CONSUMER_APP_PRIVATE_KEY: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }}
Expand Down Expand Up @@ -86,7 +86,7 @@ jobs:
id: librecode-app-token
uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4
with:
app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}
app-id: ${{ secrets.LIBRECODE_WORKFLOW_APP_ID }}
private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }}
owner: ${{ github.repository_owner }}
repositories: ${{ github.event.repository.name }}
Expand Down
Loading