Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 0 additions & 9 deletions .github/workflows/automation-caller.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,15 +21,9 @@ on: # zizmor: ignore[dangerous-triggers]
- created
pull_request_target:
types:
- assigned
- closed
- edited
- labeled
- opened
- reopened
- review_request_removed
- review_requested
- unassigned
schedule:
- cron: 1 0 * * 1
workflow_dispatch: {}
Expand All @@ -41,9 +35,6 @@ jobs:
name: Run automations
uses: learningequality/.github/.github/workflows/automation.yml@main
secrets:
CONTRIBUTIONS_SHEET_NAME: ${{ secrets.CONTRIBUTIONS_SHEET_NAME }}
CONTRIBUTIONS_SPREADSHEET_ID: ${{ secrets.CONTRIBUTIONS_SPREADSHEET_ID }}
GH_UPLOADER_GCP_SA_CREDENTIALS: ${{ secrets.GH_UPLOADER_GCP_SA_CREDENTIALS }}
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
SLACK_COMMUNITY_NOTIFICATIONS_WEBHOOK_URL: ${{ secrets.SLACK_COMMUNITY_NOTIFICATIONS_WEBHOOK_URL }}
Expand Down
52 changes: 52 additions & 0 deletions .github/workflows/automation-group-issues.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
# This file is generated by scripts/generate-automation.js from automation-registry.yml.
# Do not edit it by hand - edit the registry and run:
# node scripts/generate-automation.js
#
# Reusable workflow called from automation.yml: the automations triggered by issues.
name: "Automation: Issues"
on:
workflow_call:
secrets:
LE_BOT_APP_ID:
description: "Forwarded to: issue-open, issue-label-header, good-first-issue-comment, community-contribution-label"
required: true
LE_BOT_PRIVATE_KEY:
description: "Forwarded to: issue-open, issue-label-header, good-first-issue-comment, community-contribution-label"
required: true
jobs:
issue-open:
name: Issue Open
if: ${{ github.event_name == 'issues' && contains(fromJSON('["opened","reopened"]'), github.event.action) }}
uses: learningequality/.github/.github/workflows/manage-issue-header.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
issue-label-header:
name: Issue Label Header
if: ${{ github.event_name == 'issues' && contains(fromJSON('["labeled","unlabeled"]'), github.event.action) && github.event.label.name == 'help wanted' }}
uses: learningequality/.github/.github/workflows/manage-issue-header.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
good-first-issue-comment:
name: Good First Issue Comment
if: ${{ github.event_name == 'issues' && github.event.action == 'labeled' && (github.event.label.name == 'good first issue' || github.event.label.name == 'help wanted') }}
uses: learningequality/.github/.github/workflows/good-first-issue-comment.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
community-contribution-label:
name: Community Contribution Label
if: ${{ github.event_name == 'issues' && contains(fromJSON('["assigned","unassigned"]'), github.event.action) }}
uses: learningequality/.github/.github/workflows/community-contribution-label.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
56 changes: 56 additions & 0 deletions .github/workflows/automation-group-pull-request-target.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# This file is generated by scripts/generate-automation.js from automation-registry.yml.
# Do not edit it by hand - edit the registry and run:
# node scripts/generate-automation.js
#
# Reusable workflow called from automation.yml: the automations triggered by pull_request_target.
name: "Automation: Pull Request Target"
on:
workflow_call:
secrets:
LE_BOT_APP_ID:
description: "Forwarded to: review-requested, pull-request-label, dependabot-reviewer, contributor-pr-reply"
required: true
LE_BOT_PRIVATE_KEY:
description: "Forwarded to: review-requested, pull-request-label, dependabot-reviewer, contributor-pr-reply"
required: true
SLACK_COMMUNITY_NOTIFICATIONS_WEBHOOK_URL:
description: "Forwarded to: contributor-pr-reply"
required: false
jobs:
review-requested:
name: Review Requested
if: ${{ github.event_name == 'pull_request_target' && github.event.action == 'review_requested' }}
uses: learningequality/.github/.github/workflows/review-requested.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
pull-request-label:
name: Pull Request Label
if: ${{ github.event_name == 'pull_request_target' && github.event.action == 'labeled' }}
uses: learningequality/.github/.github/workflows/pull-request-label.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
dependabot-reviewer:
name: Dependabot Reviewer
if: ${{ github.event_name == 'pull_request_target' && github.event.action == 'opened' && github.event.pull_request.user.login == 'dependabot[bot]' }}
uses: learningequality/.github/.github/workflows/dependabot-reviewer.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
contributor-pr-reply:
name: Contributor PR Reply
if: ${{ github.event_name == 'pull_request_target' && github.event.action == 'opened' }}
uses: learningequality/.github/.github/workflows/contributor-pr-reply.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
SLACK_COMMUNITY_NOTIFICATIONS_WEBHOOK_URL: ${{ secrets.SLACK_COMMUNITY_NOTIFICATIONS_WEBHOOK_URL }}
95 changes: 15 additions & 80 deletions .github/workflows/automation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,25 +2,26 @@
# Do not edit it by hand - edit the registry and run:
# node scripts/generate-automation.js
#
# Reusable workflow: one job per automation, gated on the original triggering event/action.
# Reusable workflow: one job per automation, or per group of automations sharing trigger events,
# gated on the original triggering event/action.
name: Automation
on:
workflow_call:
secrets:
CONTRIBUTIONS_SHEET_NAME:
description: "Forwarded to: update-pr-spreadsheet"
description: Unused - accepted until every consumer stops forwarding it
required: false
CONTRIBUTIONS_SPREADSHEET_ID:
description: "Forwarded to: update-pr-spreadsheet"
description: Unused - accepted until every consumer stops forwarding it
required: false
GH_UPLOADER_GCP_SA_CREDENTIALS:
description: "Forwarded to: update-pr-spreadsheet"
description: Unused - accepted until every consumer stops forwarding it
required: false
LE_BOT_APP_ID:
description: "Forwarded to: review-requested, pull-request-label, dependabot-reviewer, contributor-pr-reply, issue-open, issue-label-header, good-first-issue-comment, update-pr-spreadsheet, community-contribution-label, contributor-issue-comment, unassign-inactive-issues"
description: "Forwarded to: review-requested, pull-request-label, dependabot-reviewer, contributor-pr-reply, issue-open, issue-label-header, good-first-issue-comment, community-contribution-label, contributor-issue-comment, unassign-inactive-issues"
required: true
LE_BOT_PRIVATE_KEY:
description: "Forwarded to: review-requested, pull-request-label, dependabot-reviewer, contributor-pr-reply, issue-open, issue-label-header, good-first-issue-comment, update-pr-spreadsheet, community-contribution-label, contributor-issue-comment, unassign-inactive-issues"
description: "Forwarded to: review-requested, pull-request-label, dependabot-reviewer, contributor-pr-reply, issue-open, issue-label-header, good-first-issue-comment, community-contribution-label, contributor-issue-comment, unassign-inactive-issues"
required: true
SLACK_COMMUNITY_NOTIFICATIONS_WEBHOOK_URL:
description: "Forwarded to: contributor-pr-reply, contributor-issue-comment, unassign-inactive-issues"
Expand All @@ -29,86 +30,20 @@ on:
description: "Forwarded to: contributor-issue-comment"
required: false
jobs:
review-requested:
name: Review Requested
if: ${{ github.event_name == 'pull_request_target' && github.event.action == 'review_requested' }}
uses: learningequality/.github/.github/workflows/review-requested.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
pull-request-label:
name: Pull Request Label
if: ${{ github.event_name == 'pull_request_target' && github.event.action == 'labeled' }}
uses: learningequality/.github/.github/workflows/pull-request-label.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
dependabot-reviewer:
name: Dependabot Reviewer
if: ${{ github.event_name == 'pull_request_target' && github.event.action == 'opened' && github.event.pull_request.user.login == 'dependabot[bot]' }}
uses: learningequality/.github/.github/workflows/dependabot-reviewer.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
contributor-pr-reply:
name: Contributor PR Reply
if: ${{ github.event_name == 'pull_request_target' && github.event.action == 'opened' }}
uses: learningequality/.github/.github/workflows/contributor-pr-reply.yml@main
pull-request-target:
name: Pull Request Target
if: ${{ (github.event_name == 'pull_request_target' && github.event.action == 'review_requested') || (github.event_name == 'pull_request_target' && github.event.action == 'labeled') || (github.event_name == 'pull_request_target' && github.event.action == 'opened' && github.event.pull_request.user.login == 'dependabot[bot]') || (github.event_name == 'pull_request_target' && github.event.action == 'opened') }}
uses: learningequality/.github/.github/workflows/automation-group-pull-request-target.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
SLACK_COMMUNITY_NOTIFICATIONS_WEBHOOK_URL: ${{ secrets.SLACK_COMMUNITY_NOTIFICATIONS_WEBHOOK_URL }}
issue-open:
name: Issue Open
if: ${{ github.event_name == 'issues' && contains(fromJSON('["opened","reopened"]'), github.event.action) }}
uses: learningequality/.github/.github/workflows/manage-issue-header.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
issue-label-header:
name: Issue Label Header
if: ${{ github.event_name == 'issues' && contains(fromJSON('["labeled","unlabeled"]'), github.event.action) && github.event.label.name == 'help wanted' }}
uses: learningequality/.github/.github/workflows/manage-issue-header.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
good-first-issue-comment:
name: Good First Issue Comment
if: ${{ github.event_name == 'issues' && github.event.action == 'labeled' && (github.event.label.name == 'good first issue' || github.event.label.name == 'help wanted') }}
uses: learningequality/.github/.github/workflows/good-first-issue-comment.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
update-pr-spreadsheet:
name: Update PR Spreadsheet
if: ${{ github.event_name == 'pull_request_target' && contains(fromJSON('["assigned","unassigned","opened","closed","reopened","edited","review_requested","review_request_removed"]'), github.event.action) }}
uses: learningequality/.github/.github/workflows/update-pr-spreadsheet.yml@main
permissions:
contents: read
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
CONTRIBUTIONS_SPREADSHEET_ID: ${{ secrets.CONTRIBUTIONS_SPREADSHEET_ID }}
CONTRIBUTIONS_SHEET_NAME: ${{ secrets.CONTRIBUTIONS_SHEET_NAME }}
GH_UPLOADER_GCP_SA_CREDENTIALS: ${{ secrets.GH_UPLOADER_GCP_SA_CREDENTIALS }}
community-contribution-label:
name: Community Contribution Label
if: ${{ github.event_name == 'issues' && contains(fromJSON('["assigned","unassigned"]'), github.event.action) }}
uses: learningequality/.github/.github/workflows/community-contribution-label.yml@main
issues:
name: Issues
if: ${{ (github.event_name == 'issues' && contains(fromJSON('["opened","reopened"]'), github.event.action)) || (github.event_name == 'issues' && contains(fromJSON('["labeled","unlabeled"]'), github.event.action) && github.event.label.name == 'help wanted') || (github.event_name == 'issues' && github.event.action == 'labeled' && (github.event.label.name == 'good first issue' || github.event.label.name == 'help wanted')) || (github.event_name == 'issues' && contains(fromJSON('["assigned","unassigned"]'), github.event.action)) }}
uses: learningequality/.github/.github/workflows/automation-group-issues.yml@main
permissions:
contents: read
secrets:
Expand Down
44 changes: 16 additions & 28 deletions .github/workflows/update-pr-spreadsheet.yml
Original file line number Diff line number Diff line change
@@ -1,33 +1,21 @@
name: Update community pull requests spreadsheet
on:
workflow_call:
secrets:
LE_BOT_APP_ID:
description: 'GitHub App ID for authentication'
required: true
LE_BOT_PRIVATE_KEY:
description: 'GitHub App Private Key for authentication'
required: true
CONTRIBUTIONS_SPREADSHEET_ID:
required: true
CONTRIBUTIONS_SHEET_NAME:
required: true
GH_UPLOADER_GCP_SA_CREDENTIALS:
required: true
schedule:
- cron: '30 2 * * *'
workflow_dispatch:
inputs:
days:
description: 'Include PRs updated in the last N days'
default: '2'
dry_run:
description: 'Log the rows instead of writing them'
type: boolean
default: false
permissions:
contents: read
jobs:
check-if-contributor:
name: Check if author is contributor
uses: learningequality/.github/.github/workflows/is-contributor.yml@main
secrets:
LE_BOT_APP_ID: ${{ secrets.LE_BOT_APP_ID }}
LE_BOT_PRIVATE_KEY: ${{ secrets.LE_BOT_PRIVATE_KEY }}
with:
username: ${{ github.event.pull_request.user.login }}
author_association: ${{ github.event.pull_request.author_association }}
update-spreadsheet:
needs: [check-if-contributor]
runs-on: ubuntu-latest
if: ${{ needs.check-if-contributor.outputs.is_contributor == 'true' }}
steps:
- name: Generate App Token
id: generate-token
Expand All @@ -38,9 +26,7 @@ jobs:
- name: Checkout .github repository
uses: actions/checkout@v7
with:
repository: learningequality/.github
ref: main
token: ${{ steps.generate-token.outputs.token }}
persist-credentials: false
- name: Setup Node.js
uses: actions/setup-node@v7
with:
Expand All @@ -59,3 +45,5 @@ jobs:
CONTRIBUTIONS_SPREADSHEET_ID: ${{ secrets.CONTRIBUTIONS_SPREADSHEET_ID }}
CONTRIBUTIONS_SHEET_NAME: ${{ secrets.CONTRIBUTIONS_SHEET_NAME }}
GOOGLE_CREDENTIALS: ${{ secrets.GH_UPLOADER_GCP_SA_CREDENTIALS }}
LOOKBACK_DAYS: ${{ inputs.days || '2' }}
DRY_RUN: ${{ inputs.dry_run || false }}
4 changes: 2 additions & 2 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ repos:
rev: v0.14.0
hooks:
- id: yamlfmt
exclude: '^tests/cassettes|^\.github/workflows/automation(-caller)?\.yml$|^automation-template\.yml$'
exclude: '^tests/cassettes|^\.github/workflows/automation(-caller|-group-.+)?\.yml$|^automation-template\.yml$'
- repo: https://github.com/rhysd/actionlint
rev: v1.7.7
hooks:
Expand All @@ -26,5 +26,5 @@ repos:
name: Check automation.yml / automation-template.yml are up to date
entry: node scripts/generate-automation.js --check
language: system
files: '^(automation-registry\.yml|scripts/generate-automation\.js|\.github/workflows/automation(-caller)?\.yml|automation-template\.yml)$'
files: '^(automation-registry\.yml|scripts/generate-automation\.js|\.github/workflows/automation(-caller|-group-.+)?\.yml|automation-template\.yml)$'
pass_filenames: false
22 changes: 8 additions & 14 deletions automation-registry.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,16 +5,23 @@
# leaf - the reusable workflow file (in .github/workflows/) it dispatches to
# on - events/types (or schedule/workflow_dispatch) it should be triggered by;
# unioned across all enabled automations to build automation-template.yml's `on:` block
# if - the dispatch condition used as the job's `if:` in automation.yml
# if - the dispatch condition used as the automation's job `if:`
# secrets - secrets to declare on automation.yml and forward to the leaf;
# required/optional: whether the leaf workflow requires the secret to be set
# permissions - job-level permissions map; defaults to { contents: read } when absent;
# set explicitly for automations whose leaf uses the default GITHUB_TOKEN with write access
#
# retired_secrets lists secrets no automation uses that automation.yml still accepts, because GitHub
# fails a caller that forwards an undeclared secret. Remove one once every consumer has synced.
#
# Run `node scripts/generate-automation.js` after editing this file to regenerate
# automation.yml and automation-template.yml. `node scripts/generate-automation.js --check`
# fails if the generated files are out of date (enforced by pre-commit + CI).

retired_secrets:
- CONTRIBUTIONS_SHEET_NAME
- CONTRIBUTIONS_SPREADSHEET_ID
- GH_UPLOADER_GCP_SA_CREDENTIALS
automations:
- name: review-requested
enabled: true
Expand Down Expand Up @@ -102,19 +109,6 @@ automations:
secrets:
LE_BOT_APP_ID: required
LE_BOT_PRIVATE_KEY: required
- name: update-pr-spreadsheet
enabled: true
leaf: update-pr-spreadsheet.yml
on:
pull_request_target:
types: [assigned, unassigned, opened, closed, reopened, edited, review_requested, review_request_removed]
if: "github.event_name == 'pull_request_target' && contains(fromJSON('[\"assigned\",\"unassigned\",\"opened\",\"closed\",\"reopened\",\"edited\",\"review_requested\",\"review_request_removed\"]'), github.event.action)"
secrets:
LE_BOT_APP_ID: required
LE_BOT_PRIVATE_KEY: required
CONTRIBUTIONS_SPREADSHEET_ID: optional
CONTRIBUTIONS_SHEET_NAME: optional
GH_UPLOADER_GCP_SA_CREDENTIALS: optional
- name: community-contribution-label
enabled: true
leaf: community-contribution-label.yml
Expand Down
Loading
Loading