diff --git a/.github/workflows/update_deps.yml b/.github/workflows/update_deps.yml index 6ceeaf319e..e605219c01 100644 --- a/.github/workflows/update_deps.yml +++ b/.github/workflows/update_deps.yml @@ -25,13 +25,10 @@ jobs: steps: - uses: actions/checkout@v7 - - name: Install jq - uses: awalsh128/cache-apt-pkgs-action@latest - with: - packages: jq - - name: Check for update id: check + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | new_version="$(utils/check_upstream_version "${{ matrix.dep }}")" if [[ -n "$new_version" ]]; then diff --git a/utils/check_upstream_version b/utils/check_upstream_version index c56bfda865..df9266ea4d 100755 --- a/utils/check_upstream_version +++ b/utils/check_upstream_version @@ -20,6 +20,19 @@ github_repo() { esac } +# A version we've deliberately rejected (e.g. a broken upstream release) gets +# its update PR closed with the "wontfix" label instead of merged. Checking +# for that PR - by its branch name, which GitHub keeps even after the branch +# itself is deleted - lets us skip re-proposing it without committing +# anything to the repo. +was_rejected() { + dep="$1" + version="$2" + + count="$(gh pr list --state closed --head "update/$dep/$version" --label wontfix --json number --jq 'length' 2>/dev/null)" || return 1 + [ "${count:-0}" -gt 0 ] +} + if [ ! -f "$VERSION_FILE" ]; then echo "Missing version file for $DEP" >&2 exit 1 @@ -27,13 +40,10 @@ fi REPO="$(github_repo "$DEP")" -LATEST="$( - curl -fsSL "https://api.github.com/repos/$REPO/releases/latest" \ - | jq -r '.tag_name' -)" +LATEST="$(gh api "repos/$REPO/releases/latest" --jq '.tag_name')" CURRENT="$(cat "$VERSION_FILE")" -if [ "$LATEST" != "$CURRENT" ]; then +if [ "$LATEST" != "$CURRENT" ] && ! was_rejected "$DEP" "$LATEST"; then printf '%s\n' "$LATEST" fi