diff --git a/.github/workflows/publish-workflow-catalog.yml b/.github/workflows/publish-workflow-catalog.yml index 0210f5d..2896932 100644 --- a/.github/workflows/publish-workflow-catalog.yml +++ b/.github/workflows/publish-workflow-catalog.yml @@ -22,14 +22,31 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - name: Validate workflow update token + - name: Validate GitHub App configuration env: - WORKFLOW_UPDATE_TOKEN: ${{ secrets.WORKFLOW_UPDATE_TOKEN }} + WORKFLOW_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + WORKFLOW_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} run: | - if [ -z "$WORKFLOW_UPDATE_TOKEN" ]; then - echo "::error::WORKFLOW_UPDATE_TOKEN is not configured. It must have access to the target repositories and permission to create/update pull requests." + if [ -z "$WORKFLOW_APP_ID" ]; then + echo "::error::LIBRECODE_WORKFLOW_APP_ID is not configured." exit 1 fi + if [ -z "$WORKFLOW_APP_PRIVATE_KEY" ]; then + echo "::error::LIBRECODE_WORKFLOW_APP_PRIVATE_KEY is not configured." + exit 1 + fi + + - name: Create GitHub App token + id: app-token + uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + with: + app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} + owner: LibreCodeCoop + repositories: .github + permission-contents: write + permission-pull-requests: write + permission-workflows: write - name: Checkout workflow source uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -40,7 +57,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: LibreCodeCoop/.github - token: ${{ secrets.WORKFLOW_UPDATE_TOKEN }} + token: ${{ steps.app-token.outputs.token }} persist-credentials: false path: catalog @@ -54,7 +71,7 @@ jobs: - name: Create catalog update pull request uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 with: - token: ${{ secrets.WORKFLOW_UPDATE_TOKEN }} + token: ${{ steps.app-token.outputs.token }} path: catalog commit-message: 'chore: sync LibreCode workflow catalog' committer: GitHub diff --git a/.github/workflows/sync-consumers.yml b/.github/workflows/sync-consumers.yml index 428b58f..e3a85f7 100644 --- a/.github/workflows/sync-consumers.yml +++ b/.github/workflows/sync-consumers.yml @@ -26,15 +26,6 @@ jobs: outputs: matrix: ${{ steps.matrix.outputs.matrix }} steps: - - name: Validate workflow update token - env: - WORKFLOW_UPDATE_TOKEN: ${{ secrets.WORKFLOW_UPDATE_TOKEN }} - run: | - if [ -z "$WORKFLOW_UPDATE_TOKEN" ]; then - echo "::error::WORKFLOW_UPDATE_TOKEN is not configured. It must have access to the target repositories and permission to create/update pull requests." - exit 1 - fi - - name: Checkout workflow source uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -54,6 +45,32 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: + - name: Validate GitHub App configuration + env: + WORKFLOW_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + WORKFLOW_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} + run: | + if [ -z "$WORKFLOW_APP_ID" ]; then + echo "::error::LIBRECODE_WORKFLOW_APP_ID is not configured." + exit 1 + fi + if [ -z "$WORKFLOW_APP_PRIVATE_KEY" ]; then + echo "::error::LIBRECODE_WORKFLOW_APP_PRIVATE_KEY is not configured." + exit 1 + fi + + - name: Create GitHub App token + id: app-token + uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + with: + app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} + owner: LibreCodeCoop + repositories: ${{ matrix.repository_name }} + permission-contents: write + permission-pull-requests: write + permission-workflows: write + - name: Checkout workflow source uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -64,7 +81,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: ${{ matrix.repository }} - token: ${{ secrets.WORKFLOW_UPDATE_TOKEN }} + token: ${{ steps.app-token.outputs.token }} persist-credentials: false path: target @@ -87,7 +104,7 @@ jobs: if: ${{ steps.sync.outcome == 'success' }} uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 with: - token: ${{ secrets.WORKFLOW_UPDATE_TOKEN }} + token: ${{ steps.app-token.outputs.token }} path: target commit-message: 'ci: sync LibreCode workflow templates' committer: GitHub diff --git a/scripts/sync_consumer.py b/scripts/sync_consumer.py index 916c3f6..92ac504 100644 --- a/scripts/sync_consumer.py +++ b/scripts/sync_consumer.py @@ -85,6 +85,7 @@ def matrix(consumers: list[Consumer]) -> dict[str, list[dict[str, object]]]: "include": [ { "repository": consumer.repository, + "repository_name": consumer.repository.split("/", 1)[1], "workflows": list(consumer.workflows), } for consumer in consumers diff --git a/tests/test_sync_consumer.py b/tests/test_sync_consumer.py index e9f8099..f3501f1 100644 --- a/tests/test_sync_consumer.py +++ b/tests/test_sync_consumer.py @@ -58,6 +58,7 @@ def test_load_consumers_and_matrix(self) -> None: "include": [ { "repository": "LibreCodeCoop/extract", + "repository_name": "extract", "workflows": ["reuse.yml"], } ]