| 
 | 1 | +name: Auto spotless, part 2  | 
 | 2 | +on:  | 
 | 3 | +  workflow_run:  | 
 | 4 | +    workflows:  | 
 | 5 | +      - "Auto spotless, part 1"  | 
 | 6 | +    types:  | 
 | 7 | +      - completed  | 
 | 8 | + | 
 | 9 | +concurrency:  | 
 | 10 | +  group: ${{ github.workflow }}-${{ github.event.pull_request.number }}  | 
 | 11 | +  cancel-in-progress: true  | 
 | 12 | + | 
 | 13 | +permissions:  | 
 | 14 | +  contents: read  | 
 | 15 | + | 
 | 16 | +jobs:  | 
 | 17 | +  apply:  | 
 | 18 | +    runs-on: ubuntu-latest  | 
 | 19 | +    permissions:  | 
 | 20 | +      contents: write  | 
 | 21 | +      pull-requests: write  | 
 | 22 | +    steps:  | 
 | 23 | +      - id: download-patch  | 
 | 24 | +        name: Download patch  | 
 | 25 | + | 
 | 26 | +        with:  | 
 | 27 | +          # this script copied from  | 
 | 28 | +          # https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#using-data-from-the-triggering-workflow  | 
 | 29 | +          script: |  | 
 | 30 | +            let allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({  | 
 | 31 | +               owner: context.repo.owner,  | 
 | 32 | +               repo: context.repo.repo,  | 
 | 33 | +               run_id: context.payload.workflow_run.id  | 
 | 34 | +            });  | 
 | 35 | +            let patchArtifact = allArtifacts.data.artifacts.filter((artifact) => {  | 
 | 36 | +              return artifact.name.startsWith("patch-")  | 
 | 37 | +            })[0];  | 
 | 38 | +            if (!patchArtifact) {  | 
 | 39 | +              core.info('No patch to apply.');  | 
 | 40 | +              return;  | 
 | 41 | +            }  | 
 | 42 | +            let download = await github.rest.actions.downloadArtifact({  | 
 | 43 | +               owner: context.repo.owner,  | 
 | 44 | +               repo: context.repo.repo,  | 
 | 45 | +               artifact_id: patchArtifact.id,  | 
 | 46 | +               archive_format: 'zip'  | 
 | 47 | +            });  | 
 | 48 | +            const fs = require('fs');  | 
 | 49 | +            const path = require('path');  | 
 | 50 | +            const temp = '${{ runner.temp }}/artifacts';  | 
 | 51 | +            if (!fs.existsSync(temp)){  | 
 | 52 | +              fs.mkdirSync(temp);  | 
 | 53 | +            }  | 
 | 54 | +            fs.writeFileSync(path.join(temp, 'patch.zip'), Buffer.from(download.data));  | 
 | 55 | +            core.setOutput("exists", "true");  | 
 | 56 | +            core.setOutput("pr-number", patchArtifact.name.substring("patch-".length));  | 
 | 57 | +
  | 
 | 58 | +      - name: Unzip patch  | 
 | 59 | +        if: steps.download-patch.outputs.exists == 'true'  | 
 | 60 | +        working-directory: ${{ runner.temp }}/artifacts  | 
 | 61 | +        run: unzip patch.zip  | 
 | 62 | + | 
 | 63 | +      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2  | 
 | 64 | +        if: steps.download-patch.outputs.exists == 'true'  | 
 | 65 | + | 
 | 66 | +      - name: Check out PR branch  | 
 | 67 | +        if: steps.download-patch.outputs.exists == 'true'  | 
 | 68 | +        env:  | 
 | 69 | +          GH_TOKEN: ${{ github.token }}  | 
 | 70 | +        run: gh pr checkout ${{ steps.download-patch.outputs.pr-number }}  | 
 | 71 | + | 
 | 72 | +      - name: Use CLA approved github bot  | 
 | 73 | +        if: steps.download-patch.outputs.exists == 'true'  | 
 | 74 | +        # IMPORTANT do not call the .github/scripts/use-cla-approved-bot.sh  | 
 | 75 | +        # since that script could have been compromised in the PR branch  | 
 | 76 | +        run: |  | 
 | 77 | +          git config user.name otelbot  | 
 | 78 | +          git config user.email [email protected]  | 
 | 79 | +
  | 
 | 80 | +      - uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6  | 
 | 81 | +        if: steps.download-patch.outputs.exists == 'true'  | 
 | 82 | +        id: otelbot-token  | 
 | 83 | +        with:  | 
 | 84 | +          app-id: ${{ vars.OTELBOT_APP_ID }}  | 
 | 85 | +          private-key: ${{ secrets.OTELBOT_PRIVATE_KEY }}  | 
 | 86 | + | 
 | 87 | +      - name: Apply patch and push  | 
 | 88 | +        if: steps.download-patch.outputs.exists == 'true'  | 
 | 89 | +        env:  | 
 | 90 | +          GH_TOKEN: ${{ steps.otelbot-token.outputs.token }}  | 
 | 91 | +        run: |  | 
 | 92 | +          git apply "${{ runner.temp }}/artifacts/patch"  | 
 | 93 | +          git commit -a -m "./gradlew spotlessApply"  | 
 | 94 | +          git push  | 
 | 95 | +
  | 
 | 96 | +      - if: steps.download-patch.outputs.exists == 'true' && success()  | 
 | 97 | +        env:  | 
 | 98 | +          GH_TOKEN: ${{ steps.otelbot-token.outputs.token }}  | 
 | 99 | +        run: |  | 
 | 100 | +          gh pr comment ${{ steps.download-patch.outputs.pr-number }} --body "🔧 The result from \`./gradlew spotlessApply\` was committed to the PR branch."  | 
 | 101 | +
  | 
 | 102 | +      - if: steps.download-patch.outputs.exists == 'true' && failure()  | 
 | 103 | +        env:  | 
 | 104 | +          GH_TOKEN: ${{ steps.otelbot-token.outputs.token }}  | 
 | 105 | +        run: |  | 
 | 106 | +          gh pr comment ${{ steps.download-patch.outputs.pr-number }} --body "❌ The result from \`./gradlew spotlessApply\` could not be committed to the PR branch, see logs: $GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID."  | 
0 commit comments