Skip to content

Commit a079d0a

Browse files
committed
More secure
1 parent c0d3fc2 commit a079d0a

File tree

3 files changed

+151
-106
lines changed

3 files changed

+151
-106
lines changed
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
name: Auto spotless, part 1
2+
on:
3+
pull_request:
4+
types:
5+
- opened
6+
- synchronize
7+
8+
concurrency:
9+
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
10+
cancel-in-progress: true
11+
12+
permissions:
13+
contents: read
14+
15+
jobs:
16+
check:
17+
runs-on: ubuntu-latest
18+
steps:
19+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
20+
21+
- name: Free disk space
22+
run: .github/scripts/gha-free-disk-space.sh
23+
24+
- name: Set up JDK for running Gradle
25+
uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
26+
with:
27+
distribution: temurin
28+
java-version-file: .java-version
29+
30+
- name: Check out PR branch
31+
env:
32+
GH_TOKEN: ${{ github.token }}
33+
run: gh pr checkout ${{ github.event.pull_request.number }}
34+
35+
- name: Spotless
36+
run: ./gradlew spotlessApply
37+
38+
- id: create-patch-file
39+
name: Create patch file
40+
run: |
41+
git diff > patch
42+
if [ -s patch ]; then
43+
echo "non-empty=true" >> "$GITHUB_OUTPUT"
44+
fi
45+
46+
- name: Upload patch file
47+
if: steps.create-patch-file.outputs.non-empty == 'true'
48+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
49+
with:
50+
path: patch
51+
name: patch-${{ github.event.pull_request.number }}
Lines changed: 100 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,100 @@
1+
name: Auto spotless
2+
on:
3+
workflow_run:
4+
workflows:
5+
- "Auto spotless, part 1"
6+
types:
7+
- completed
8+
9+
concurrency:
10+
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
11+
cancel-in-progress: true
12+
13+
permissions:
14+
contents: read
15+
16+
jobs:
17+
apply:
18+
runs-on: ubuntu-latest
19+
needs: check
20+
if: needs.check.outputs.patch-created == 'true'
21+
permissions:
22+
contents: write
23+
pull-requests: write
24+
steps:
25+
- id: download-patch
26+
name: Download patch
27+
uses: actions/[email protected]
28+
with:
29+
# this script copied from
30+
# https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#using-data-from-the-triggering-workflow
31+
script: |
32+
let allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({
33+
owner: context.repo.owner,
34+
repo: context.repo.repo,
35+
run_id: context.payload.workflow_run.id
36+
});
37+
let patchArtifact = allArtifacts.data.artifacts.filter((artifact) => {
38+
return artifact.name.startsWith("patch-")
39+
})[0];
40+
if (!patchArtifact) {
41+
core.info('No patch to apply.');
42+
return;
43+
}
44+
let download = await github.rest.actions.downloadArtifact({
45+
owner: context.repo.owner,
46+
repo: context.repo.repo,
47+
artifact_id: patchArtifact.id,
48+
archive_format: 'zip'
49+
});
50+
const fs = require('fs');
51+
const path = require('path');
52+
const temp = '${{ runner.temp }}/artifacts';
53+
if (!fs.existsSync(temp)){
54+
fs.mkdirSync(temp);
55+
}
56+
fs.writeFileSync(path.join(temp, 'patch.zip'), Buffer.from(download.data));
57+
core.setOutput("pr-num", patchArtifact.name.substring("patch-".length));
58+
59+
- name: Unzip patch
60+
run: unzip patch.zip -d "${{ runner.temp }}/artifacts"
61+
62+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
63+
64+
- name: Check out PR branch
65+
env:
66+
GH_TOKEN: ${{ github.token }}
67+
run: gh pr checkout ${{ steps.download-patch.outputs.pr-num }}
68+
69+
- name: Use CLA approved github bot
70+
# IMPORTANT do not call the .github/scripts/use-cla-approved-bot.sh
71+
# since that script could have been compromised in the PR branch
72+
run: |
73+
git config user.name otelbot
74+
git config user.email [email protected]
75+
76+
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
77+
id: otelbot-token
78+
with:
79+
app-id: ${{ vars.OTELBOT_APP_ID }}
80+
private-key: ${{ secrets.OTELBOT_PRIVATE_KEY }}
81+
82+
- name: Apply patch and push
83+
env:
84+
GH_TOKEN: ${{ steps.otelbot-token.outputs.token }}
85+
run: |
86+
git apply "${{ runner.temp }}/artifacts/patch"
87+
git commit -a -m "./gradlew spotlessApply"
88+
git push
89+
90+
- if: success()
91+
env:
92+
GH_TOKEN: ${{ steps.otelbot-token.outputs.token }}
93+
run: |
94+
gh pr comment ${{ steps.download-patch.outputs.pr-num }} --body "🔧 The result from \`./gradlew spotlessApply\` was committed to the PR branch."
95+
96+
- if: failure()
97+
env:
98+
GH_TOKEN: ${{ steps.otelbot-token.outputs.token }}
99+
run: |
100+
gh pr comment ${{ steps.download-patch.outputs.pr-num }} --body "❌ The result from \`./gradlew spotlessApply\` could not be committed to the PR branch, see logs: $GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID."

.github/workflows/auto-spotless.yml

Lines changed: 0 additions & 106 deletions
This file was deleted.

0 commit comments

Comments
 (0)