Skip to content

Commit c35a77d

Browse files
authored
Merge branch 'main' into dependabot/gradle/main/com.fasterxml.jackson.dataformat-jackson-dataformat-xml-2.22.2
2 parents 46fe534 + 4b5d7d0 commit c35a77d

9 files changed

Lines changed: 123 additions & 14 deletions

File tree

‎.github/workflows/codeql-analysis.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ jobs:
3535
# Initializes the CodeQL tools for scanning.
3636
# Must run AFTER setup-java so CodeQL hooks into the correct JDK.
3737
- name: Initialize CodeQL
38-
uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
38+
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4
3939
with:
4040
languages: 'java'
4141

@@ -45,4 +45,4 @@ jobs:
4545
run: ./gradlew --no-build-cache clean compileJava compileTestJava
4646

4747
- name: Perform CodeQL Analysis
48-
uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
48+
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4

‎.github/workflows/dependabot-automerge.yml‎

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,9 +24,8 @@ jobs:
2424
PR_URL: ${{ github.event.pull_request.html_url }}
2525
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
2626

27-
- name: Enable auto-merge for patch and minor updates
28-
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
27+
- name: Enable auto-merge for all PRs
2928
run: gh pr merge --auto --squash "$PR_URL"
3029
env:
3130
PR_URL: ${{ github.event.pull_request.html_url }}
32-
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
31+
GH_TOKEN: ${{ secrets.BOT_PAT }}

‎docs/icon/README.md‎

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
# Icon
2+
3+
A broken method chain: one long line, then a group of shorter ones sharing a left edge, with a
4+
column guide down the right. It is the formatter's own output shape — the thing that distinguishes
5+
it is deciding *where* to break and what to line up, not laying everything out uniformly.
6+
7+
| File | Use |
8+
|---|---|
9+
| `icon.svg` | The mark. Inherits `currentColor`, so one file covers light, dark and monochrome. |
10+
| `favicon.svg` | Same geometry, guide at full strength. Below ~24px contrast is what keeps the guide visible, not shape. |
11+
| `avatar.svg` | The mark on a white rounded square, for the GitHub organisation and marketplace tiles. |
12+
| `avatar-512.png`, `avatar-128.png` | Rasterised from `avatar.svg`; GitHub organisation avatars must be raster. |
13+
14+
Regenerate the PNGs after editing the SVG:
15+
16+
```bash
17+
rsvg-convert -w 512 -h 512 docs/icon/avatar.svg -o docs/icon/avatar-512.png
18+
rsvg-convert -w 128 -h 128 docs/icon/avatar.svg -o docs/icon/avatar-128.png
19+
```
20+
21+
## What not to break
22+
23+
The mark has seven elements, which is the ceiling for 16px. Anything added has to displace
24+
something else.
25+
26+
- **The shared right edge does the work.** The first and third bars end on the same x. That
27+
implied vertical is what carries "there is a boundary" at sizes where the dashes disappear, and
28+
it costs nothing because no thin element draws it. Changing either bar's width breaks the idea
29+
silently — the icon will still look fine at 64px and mean nothing at 16px.
30+
- **The guide's rhythm must not match the bars'.** Three dashes against four bars is deliberate:
31+
mismatched rhythms read as two layers, so the boundary belongs to the format rather than to any
32+
one line. Align them and the dashes turn into decoration stuck on the bar ends.
33+
- **Check every edit at 16px first.** Every version of this mark looked fine large. The small size
34+
is the only one that rejects anything.
35+
36+
The two colours in `avatar.svg` are the only brand decision baked in here, and they are a
37+
placeholder. The white ground means that on GitHub's light theme the tile itself disappears and
38+
only the mark reads; an off-white ground keeps the tile visible if that is preferred.

‎docs/icon/avatar-128.png‎

2.6 KB
Loading

‎docs/icon/avatar-512.png‎

11.7 KB
Loading

‎docs/icon/avatar.svg‎

Lines changed: 20 additions & 0 deletions
Loading

‎docs/icon/favicon.svg‎

Lines changed: 19 additions & 0 deletions
Loading

‎docs/icon/icon.svg‎

Lines changed: 19 additions & 0 deletions
Loading

‎mise.toml‎

Lines changed: 23 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -25,17 +25,29 @@ run = "act push --job native --matrix platform:linux-aarch64"
2525
# (authenticated with admin on this repository) and the 1Password CLI (`op signin` first).
2626

2727
[tasks."gh:secrets"]
28-
description = "Set the repository's Actions secrets from 1Password (op)"
28+
description = "Set the repository's Actions and Dependabot secrets from 1Password (op)"
2929
shell = "bash -c"
3030
quiet = true # suppress mise's `[task] $ <first line>` command echo
3131
env = { NO_COLOR = "1" } # suppress gh's OSC-11 terminal-background probe
32-
run = '''
32+
run = """
3333
set -euo pipefail
3434
35-
# BOT_PAT is consumed by .github/workflows/update-pr-branch.yml, and it cannot be GITHUB_TOKEN:
36-
# a push made with GITHUB_TOKEN does not start workflow runs, so a PR branch would be brought
37-
# up to date and then never re-checked — which is the whole point of that workflow. A
38-
# fine-grained PAT scoped to this repository with Contents: read and write is enough.
35+
# BOT_PAT is consumed by update-pr-branch.yml and by the auto-merge step of
36+
# dependabot-automerge.yml, and it cannot be GITHUB_TOKEN: a push made with GITHUB_TOKEN starts no
37+
# workflow runs, so a branch would be brought up to date — or a pull request merged — and then
38+
# never re-checked.
39+
#
40+
# The token needs these repository permissions:
41+
# Pull requests Write PUT /repos/{owner}/{repo}/pulls/{n}/update-branch requires it
42+
# Contents Write pushing the updated branch and the merge commit
43+
#
44+
# It is written to BOTH secret stores. A run triggered by a Dependabot event cannot read Actions
45+
# secrets at all — it reads the Dependabot store instead — so a token present only in Actions
46+
# expands to an empty string there, and gh fails with "set the GH_TOKEN environment variable".
47+
#
48+
# --repo, because this checkout has two remotes (origin and upstream) and gh refuses to guess.
49+
repo="$(git remote get-url origin | sed -E 's#(git@github\\.com:|https://github\\.com/)##; s#\\.git$##')"
50+
3951
apply() {
4052
local name="$1" ref="$2" value
4153
if [[ "$ref" == *TODO* ]]; then
@@ -46,9 +58,11 @@ apply() {
4658
echo " Create that item in 1Password (or point the reference at an existing one), then re-run." >&2
4759
return 1
4860
fi
49-
gh secret set "$name" --body "$value"
50-
echo "✓ $name set"
61+
for store in actions dependabot; do
62+
gh secret set "$name" --app "$store" --repo "$repo" --body "$value"
63+
echo "✓ $name set ($store)"
64+
done
5165
}
5266
5367
apply BOT_PAT 'op://Private/open-java-format/GitHub/bot-pat'
54-
'''
68+
"""

0 commit comments

Comments
 (0)