Skip to content

Commit 7d32550

Browse files
committed
More secure
1 parent c0d3fc2 commit 7d32550

File tree

3 files changed

+162
-106
lines changed

3 files changed

+162
-106
lines changed
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
name: Auto spotless, part 1
2+
on:
3+
pull_request:
4+
types:
5+
- opened
6+
- synchronize
7+
8+
concurrency:
9+
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
10+
cancel-in-progress: true
11+
12+
permissions:
13+
contents: read
14+
15+
jobs:
16+
check:
17+
runs-on: ubuntu-latest
18+
steps:
19+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
20+
21+
- name: Free disk space
22+
run: .github/scripts/gha-free-disk-space.sh
23+
24+
- name: Set up JDK for running Gradle
25+
uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
26+
with:
27+
distribution: temurin
28+
java-version-file: .java-version
29+
30+
- name: Set up gradle
31+
uses: gradle/actions/setup-gradle@06832c7b30a0129d7fb559bcc6e43d26f6374244 # v4.3.1
32+
with:
33+
cache-read-only: true
34+
35+
- name: Check out PR branch
36+
env:
37+
GH_TOKEN: ${{ github.token }}
38+
run: gh pr checkout ${{ github.event.pull_request.number }}
39+
40+
- name: Spotless
41+
run: ./gradlew spotlessApply
42+
43+
- id: create-patch-file
44+
name: Create patch file
45+
run: |
46+
git diff > patch
47+
if [ -s patch ]; then
48+
echo "non-empty=true" >> "$GITHUB_OUTPUT"
49+
fi
50+
51+
- name: Upload patch file
52+
if: steps.create-patch-file.outputs.non-empty == 'true'
53+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
54+
with:
55+
path: patch
56+
name: patch-${{ github.event.pull_request.number }}
Lines changed: 106 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,106 @@
1+
name: Auto spotless, part 2
2+
on:
3+
workflow_run:
4+
workflows:
5+
- "Auto spotless, part 1"
6+
types:
7+
- completed
8+
9+
concurrency:
10+
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
11+
cancel-in-progress: true
12+
13+
permissions:
14+
contents: read
15+
16+
jobs:
17+
apply:
18+
runs-on: ubuntu-latest
19+
permissions:
20+
contents: write
21+
pull-requests: write
22+
steps:
23+
- id: download-patch
24+
name: Download patch
25+
uses: actions/github-script@v7.0.1
26+
with:
27+
# this script copied from
28+
# https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#using-data-from-the-triggering-workflow
29+
script: |
30+
let allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({
31+
owner: context.repo.owner,
32+
repo: context.repo.repo,
33+
run_id: context.payload.workflow_run.id
34+
});
35+
let patchArtifact = allArtifacts.data.artifacts.filter((artifact) => {
36+
return artifact.name.startsWith("patch-")
37+
})[0];
38+
if (!patchArtifact) {
39+
core.info('No patch to apply.');
40+
return;
41+
}
42+
let download = await github.rest.actions.downloadArtifact({
43+
owner: context.repo.owner,
44+
repo: context.repo.repo,
45+
artifact_id: patchArtifact.id,
46+
archive_format: 'zip'
47+
});
48+
const fs = require('fs');
49+
const path = require('path');
50+
const temp = '${{ runner.temp }}/artifacts';
51+
if (!fs.existsSync(temp)){
52+
fs.mkdirSync(temp);
53+
}
54+
fs.writeFileSync(path.join(temp, 'patch.zip'), Buffer.from(download.data));
55+
core.setOutput("exists", "true");
56+
core.setOutput("pr-number", patchArtifact.name.substring("patch-".length));
57+
58+
- name: Unzip patch
59+
if: steps.download-patch.outputs.exists == 'true'
60+
working-directory: ${{ runner.temp }}/artifacts
61+
run: unzip patch.zip
62+
63+
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
64+
if: steps.download-patch.outputs.exists == 'true'
65+
66+
- name: Check out PR branch
67+
if: steps.download-patch.outputs.exists == 'true'
68+
env:
69+
GH_TOKEN: ${{ github.token }}
70+
run: gh pr checkout ${{ steps.download-patch.outputs.pr-number }}
71+
72+
- name: Use CLA approved github bot
73+
if: steps.download-patch.outputs.exists == 'true'
74+
# IMPORTANT do not call the .github/scripts/use-cla-approved-bot.sh
75+
# since that script could have been compromised in the PR branch
76+
run: |
77+
git config user.name otelbot
78+
git config user.email 197425009+otelbot@users.noreply.github.com
79+
80+
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
81+
if: steps.download-patch.outputs.exists == 'true'
82+
id: otelbot-token
83+
with:
84+
app-id: ${{ vars.OTELBOT_APP_ID }}
85+
private-key: ${{ secrets.OTELBOT_PRIVATE_KEY }}
86+
87+
- name: Apply patch and push
88+
if: steps.download-patch.outputs.exists == 'true'
89+
env:
90+
GH_TOKEN: ${{ steps.otelbot-token.outputs.token }}
91+
run: |
92+
git apply "${{ runner.temp }}/artifacts/patch"
93+
git commit -a -m "./gradlew spotlessApply"
94+
git push
95+
96+
- if: steps.download-patch.outputs.exists == 'true' && success()
97+
env:
98+
GH_TOKEN: ${{ steps.otelbot-token.outputs.token }}
99+
run: |
100+
gh pr comment ${{ steps.download-patch.outputs.pr-number }} --body "🔧 The result from \`./gradlew spotlessApply\` was committed to the PR branch."
101+
102+
- if: steps.download-patch.outputs.exists == 'true' && failure()
103+
env:
104+
GH_TOKEN: ${{ steps.otelbot-token.outputs.token }}
105+
run: |
106+
gh pr comment ${{ steps.download-patch.outputs.pr-number }} --body "❌ The result from \`./gradlew spotlessApply\` could not be committed to the PR branch, see logs: $GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID."

.github/workflows/auto-spotless.yml

Lines changed: 0 additions & 106 deletions
This file was deleted.

0 commit comments

Comments
 (0)