Repository navigation
Update libs from CodeOnTheGo #58
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Update libs from CodeOnTheGo | |
| on: | |
| workflow_dispatch: | |
| permissions: | |
| contents: write | |
| jobs: | |
| release: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 45 | |
| steps: | |
| - name: Checkout plugin-examples | |
| uses: actions/checkout@v4 | |
| with: | |
| # PAT from a repo admin so the libs/ push bypasses the main ruleset. | |
| # A fine-grained PAT must use the organization as its resource owner, | |
| # not a personal account, or every push returns 403. The next step | |
| # checks this. GITHUB_TOKEN is only a fallback to keep checkout | |
| # working; it cannot bypass the ruleset, so the check rejects it. | |
| token: ${{ secrets.ADMIN_PERSONAL_ACCESS_TOKEN || github.token }} | |
| # The build below takes ~30 minutes. Without this guard, a token that | |
| # cannot write to this repo throws all of that away at "Commit updated | |
| # jars". Check the token first so the run fails in seconds instead. | |
| - name: Verify the push token | |
| env: | |
| ADMIN_PAT: ${{ secrets.ADMIN_PERSONAL_ACCESS_TOKEN }} | |
| GH_TOKEN: ${{ secrets.ADMIN_PERSONAL_ACCESS_TOKEN || github.token }} | |
| run: | | |
| org="${GITHUB_REPOSITORY%%/*}" | |
| if [ -z "$ADMIN_PAT" ]; then | |
| echo "::error::ADMIN_PERSONAL_ACCESS_TOKEN is not set. GITHUB_TOKEN cannot bypass the ${org} main ruleset, so the push would fail." | |
| exit 1 | |
| fi | |
| if ! repo=$(gh api "repos/${GITHUB_REPOSITORY}" 2>/dev/null); then | |
| echo "::error::The token cannot see ${GITHUB_REPOSITORY}. A fine-grained PAT must use resource owner '${org}' (the organization). A token owned by a personal account cannot reach ${org} repositories." | |
| exit 1 | |
| fi | |
| who=$(gh api user --jq .login 2>/dev/null || echo '(unknown)') | |
| push=$(printf '%s' "$repo" | jq -r '.permissions.push // false') | |
| echo "Token identity: ${who}. Push permission: ${push}." | |
| if [ "$push" != "true" ]; then | |
| echo "::error::The token authenticates as '${who}' but cannot write to ${GITHUB_REPOSITORY}. Grant it 'Contents: Read and write' with resource owner '${org}'." | |
| exit 1 | |
| fi | |
| - name: Set up JDK 17 | |
| uses: actions/setup-java@v4 | |
| with: | |
| distribution: temurin | |
| java-version: '17' | |
| - name: Install uv | |
| uses: astral-sh/setup-uv@v5 | |
| - name: Set up Gradle | |
| uses: gradle/actions/setup-gradle@v3 | |
| with: | |
| cache-disabled: true | |
| add-job-summary: 'never' | |
| - name: Compute release tag | |
| id: tag | |
| env: | |
| RUN_NUMBER: ${{ github.run_number }} | |
| run: echo "name=build-$(date -u +%Y-%m-%d)-${RUN_NUMBER}" >> "$GITHUB_OUTPUT" | |
| # Refreshes libs/ from CodeOnTheGo@stage, then proves every plugin still | |
| # compiles against the new jars. Templates use no jars, so none are built. | |
| - name: Refresh libs and build plugins | |
| run: ./scripts/build-plugins.sh --ref stage | |
| - name: Commit updated jars | |
| id: commit | |
| run: | | |
| # 12 characters, matching what update-libs.sh records as libs_revision and | |
| # what publish-addons.yml parses back out of this subject, so the same jars | |
| # yield one comparable sha everywhere. | |
| sha=$(git -C .cache/CodeOnTheGo rev-parse --short=12 HEAD) | |
| git config user.name "ADFA" | |
| git config user.email "dev-team@appdevforall.org" | |
| git add libs/ | |
| if git diff --cached --quiet; then | |
| echo "No changes to libs/ — nothing to commit." | |
| else | |
| git commit -m "chore: update libs from CodeOnTheGo@${sha}" | |
| git push | |
| fi | |
| echo "codeonthego_sha=${sha}" >> "$GITHUB_OUTPUT" | |
| echo "head_sha=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT" | |
| - name: Publish release | |
| uses: softprops/action-gh-release@v2 | |
| with: | |
| tag_name: ${{ steps.tag.outputs.name }} | |
| target_commitish: ${{ steps.commit.outputs.head_sha }} | |
| body: Built against CodeOnTheGo@${{ steps.commit.outputs.codeonthego_sha }}. | |
| fail_on_unmatched_files: true | |
| files: 'plugins/*/build/plugin/*.cgp' |