Repository navigation
Monitor Upstream Runner Releases #8
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Monitor Upstream Runner Releases | |
| on: | |
| schedule: | |
| - cron: '17 */6 * * *' | |
| workflow_dispatch: | |
| inputs: | |
| force_publish: | |
| description: 'Dispatch publish/release workflows even if upstream metadata is unchanged' | |
| required: false | |
| type: boolean | |
| default: false | |
| permissions: | |
| contents: write | |
| actions: write | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event_name == 'workflow_dispatch' && github.run_id || 'schedule' }} | |
| cancel-in-progress: false | |
| env: | |
| UPSTREAM_REPO: actions/runner | |
| TRACK_FILE: .github/upstream/actions-runner.json | |
| TARGET_WORKFLOW_PUBLISH: publish.yml | |
| TARGET_WORKFLOW_RELEASE: release.yml | |
| GIT_CONFIG_USER_NAME: github-actions[bot] | |
| GIT_CONFIG_USER_EMAIL: 41898282+github-actions[bot]@users.noreply.github.com | |
| jobs: | |
| monitor: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Fetch upstream runner metadata and detect changes | |
| id: check | |
| run: | | |
| set -euo pipefail | |
| mkdir -p "$(dirname "${TRACK_FILE}")" | |
| echo "--- Fetching upstream metadata ---" | |
| echo "Repo: ${UPSTREAM_REPO}" | |
| LATEST_RELEASE="$(curl -fsSL \ | |
| -H "Accept: application/vnd.github+json" \ | |
| "https://api.github.com/repos/${UPSTREAM_REPO}/releases/latest")" | |
| upstream_version="$(jq -r '.tag_name' <<<"${LATEST_RELEASE}" | sed 's/^v//')" | |
| upstream_commit="$(jq -r '.target_commitish' <<<"${LATEST_RELEASE}")" | |
| upstream_date="$(jq -r '.published_at' <<<"${LATEST_RELEASE}")" | |
| echo "Upstream version: ${upstream_version}" | |
| echo "Upstream commit: ${upstream_commit}" | |
| echo "Upstream date: ${upstream_date}" | |
| if [ -z "${upstream_version}" ] || [ "${upstream_version}" = "null" ]; then | |
| echo "ERROR: Failed to fetch upstream version" | |
| exit 1 | |
| fi | |
| # Write upstream snapshot as sorted JSON for stable comparison | |
| jq -n \ | |
| --arg version "${upstream_version}" \ | |
| --arg commit "${upstream_commit}" \ | |
| --arg date "${upstream_date}" \ | |
| '{"version": $version, "commit": $commit, "published_at": $date}' \ | |
| > /tmp/upstream-runner.json | |
| { | |
| echo "upstream_version=${upstream_version}" | |
| echo "upstream_commit=${upstream_commit}" | |
| echo "upstream_date=${upstream_date}" | |
| } >> "$GITHUB_OUTPUT" | |
| echo "--- Comparing with tracked metadata ---" | |
| if [ -f "${TRACK_FILE}" ]; then | |
| echo "Tracked file exists: ${TRACK_FILE}" | |
| cat "${TRACK_FILE}" | |
| echo "" | |
| if cmp -s "${TRACK_FILE}" /tmp/upstream-runner.json; then | |
| echo "Result: NO CHANGE — upstream metadata matches tracked file" | |
| echo "changed=false" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "Result: CHANGED — upstream metadata differs from tracked file" | |
| echo "Diff (tracked -> upstream):" | |
| diff "${TRACK_FILE}" /tmp/upstream-runner.json || true | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| fi | |
| else | |
| echo "Tracked file not found — treating as first run" | |
| echo "Result: CHANGED (new)" | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Update tracked metadata file | |
| if: steps.check.outputs.changed == 'true' | |
| run: | | |
| set -euo pipefail | |
| echo "Writing updated metadata to ${TRACK_FILE}" | |
| cp /tmp/upstream-runner.json "${TRACK_FILE}" | |
| echo "Updated contents:" | |
| cat "${TRACK_FILE}" | |
| - name: Commit tracked metadata changes | |
| if: steps.check.outputs.changed == 'true' | |
| env: | |
| UPSTREAM_VERSION: ${{ steps.check.outputs.upstream_version }} | |
| UPSTREAM_COMMIT: ${{ steps.check.outputs.upstream_commit }} | |
| run: | | |
| set -euo pipefail | |
| git config user.name "${GIT_CONFIG_USER_NAME}" | |
| git config user.email "${GIT_CONFIG_USER_EMAIL}" | |
| git add "${TRACK_FILE}" | |
| if git diff --cached --quiet; then | |
| echo "No tracked metadata changes to commit." | |
| exit 0 | |
| fi | |
| COMMIT_MSG="chore(ci): track actions/runner ${UPSTREAM_VERSION} (${UPSTREAM_COMMIT:0:7})" | |
| echo "Committing: ${COMMIT_MSG}" | |
| git commit -m "${COMMIT_MSG}" | |
| - name: Push tracked metadata commit | |
| if: steps.check.outputs.changed == 'true' | |
| run: | | |
| echo "Pushing commit to origin" | |
| git push | |
| echo "Push complete" | |
| - name: Trigger downstream workflows | |
| if: steps.check.outputs.changed == 'true' || (github.event_name == 'workflow_dispatch' && inputs.force_publish) | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| REPO: ${{ github.repository }} | |
| DEFAULT_BRANCH: ${{ github.event.repository.default_branch }} | |
| run: | | |
| set -euo pipefail | |
| dispatch() { | |
| local workflow="$1" | |
| echo "Dispatching ${workflow} on ${DEFAULT_BRANCH}" | |
| curl -fsSL -X POST \ | |
| -H "Accept: application/vnd.github+json" \ | |
| -H "Authorization: Bearer ${GH_TOKEN}" \ | |
| "https://api.github.com/repos/${REPO}/actions/workflows/${workflow}/dispatches" \ | |
| -d "{\"ref\":\"${DEFAULT_BRANCH}\"}" | |
| echo "Dispatch sent: ${workflow}" | |
| } | |
| dispatch "${TARGET_WORKFLOW_PUBLISH}" | |
| dispatch "${TARGET_WORKFLOW_RELEASE}" | |
| echo "All downstream workflows dispatched" | |
| - name: Publish monitor summary | |
| if: always() | |
| env: | |
| CHANGED: ${{ steps.check.outputs.changed }} | |
| UPSTREAM_VERSION: ${{ steps.check.outputs.upstream_version }} | |
| UPSTREAM_COMMIT: ${{ steps.check.outputs.upstream_commit }} | |
| UPSTREAM_DATE: ${{ steps.check.outputs.upstream_date }} | |
| EVENT_NAME: ${{ github.event_name }} | |
| FORCE_PUBLISH: ${{ inputs.force_publish }} | |
| run: | | |
| changed="${CHANGED:-false}" | |
| force="${FORCE_PUBLISH:-false}" | |
| triggered=false | |
| trigger_reason="" | |
| if [ "${changed}" = "true" ]; then | |
| triggered=true | |
| trigger_reason="upstream metadata changed" | |
| elif [ "${EVENT_NAME}" = "workflow_dispatch" ] && [ "${force}" = "true" ]; then | |
| triggered=true | |
| trigger_reason="force_publish requested via workflow_dispatch" | |
| fi | |
| { | |
| echo "## Upstream actions/runner Monitor" | |
| echo "" | |
| echo "### Upstream" | |
| echo "| Field | Value |" | |
| echo "| --- | --- |" | |
| echo "| Repo | [${UPSTREAM_REPO}](https://github.com/${UPSTREAM_REPO}) |" | |
| echo "| Version | \`${UPSTREAM_VERSION:-unknown}\` |" | |
| echo "| Commit | \`${UPSTREAM_COMMIT:-unknown}\` |" | |
| echo "| Published | \`${UPSTREAM_DATE:-unknown}\` |" | |
| echo "" | |
| echo "### Run" | |
| echo "| Field | Value |" | |
| echo "| --- | --- |" | |
| echo "| Trigger | \`${EVENT_NAME}\` |" | |
| if [ "${changed}" = "true" ]; then | |
| echo "| Upstream changed | Yes — metadata updated and committed |" | |
| else | |
| echo "| Upstream changed | No — metadata unchanged |" | |
| fi | |
| if [ "${triggered}" = "true" ]; then | |
| echo "| Downstream triggered | Yes — ${trigger_reason} |" | |
| echo "| Workflows dispatched | \`${TARGET_WORKFLOW_PUBLISH}\`, \`${TARGET_WORKFLOW_RELEASE}\` |" | |
| else | |
| echo "| Downstream triggered | No — no change detected and force_publish not set |" | |
| fi | |
| } >> "$GITHUB_STEP_SUMMARY" |