Skip to content

Monitor Upstream Runner Releases #8

Monitor Upstream Runner Releases

Monitor Upstream Runner Releases #8

name: Monitor Upstream Runner Releases
on:
schedule:
- cron: '17 */6 * * *'
workflow_dispatch:
inputs:
force_publish:
description: 'Dispatch publish/release workflows even if upstream metadata is unchanged'
required: false
type: boolean
default: false
permissions:
contents: write
actions: write
concurrency:
group: ${{ github.workflow }}-${{ github.event_name == 'workflow_dispatch' && github.run_id || 'schedule' }}
cancel-in-progress: false
env:
UPSTREAM_REPO: actions/runner
TRACK_FILE: .github/upstream/actions-runner.json
TARGET_WORKFLOW_PUBLISH: publish.yml
TARGET_WORKFLOW_RELEASE: release.yml
GIT_CONFIG_USER_NAME: github-actions[bot]
GIT_CONFIG_USER_EMAIL: 41898282+github-actions[bot]@users.noreply.github.com
jobs:
monitor:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Fetch upstream runner metadata and detect changes
id: check
run: |
set -euo pipefail
mkdir -p "$(dirname "${TRACK_FILE}")"
echo "--- Fetching upstream metadata ---"
echo "Repo: ${UPSTREAM_REPO}"
LATEST_RELEASE="$(curl -fsSL \
-H "Accept: application/vnd.github+json" \
"https://api.github.com/repos/${UPSTREAM_REPO}/releases/latest")"
upstream_version="$(jq -r '.tag_name' <<<"${LATEST_RELEASE}" | sed 's/^v//')"
upstream_commit="$(jq -r '.target_commitish' <<<"${LATEST_RELEASE}")"
upstream_date="$(jq -r '.published_at' <<<"${LATEST_RELEASE}")"
echo "Upstream version: ${upstream_version}"
echo "Upstream commit: ${upstream_commit}"
echo "Upstream date: ${upstream_date}"
if [ -z "${upstream_version}" ] || [ "${upstream_version}" = "null" ]; then
echo "ERROR: Failed to fetch upstream version"
exit 1
fi
# Write upstream snapshot as sorted JSON for stable comparison
jq -n \
--arg version "${upstream_version}" \
--arg commit "${upstream_commit}" \
--arg date "${upstream_date}" \
'{"version": $version, "commit": $commit, "published_at": $date}' \
> /tmp/upstream-runner.json
{
echo "upstream_version=${upstream_version}"
echo "upstream_commit=${upstream_commit}"
echo "upstream_date=${upstream_date}"
} >> "$GITHUB_OUTPUT"
echo "--- Comparing with tracked metadata ---"
if [ -f "${TRACK_FILE}" ]; then
echo "Tracked file exists: ${TRACK_FILE}"
cat "${TRACK_FILE}"
echo ""
if cmp -s "${TRACK_FILE}" /tmp/upstream-runner.json; then
echo "Result: NO CHANGE — upstream metadata matches tracked file"
echo "changed=false" >> "$GITHUB_OUTPUT"
else
echo "Result: CHANGED — upstream metadata differs from tracked file"
echo "Diff (tracked -> upstream):"
diff "${TRACK_FILE}" /tmp/upstream-runner.json || true
echo "changed=true" >> "$GITHUB_OUTPUT"
fi
else
echo "Tracked file not found — treating as first run"
echo "Result: CHANGED (new)"
echo "changed=true" >> "$GITHUB_OUTPUT"
fi
- name: Update tracked metadata file
if: steps.check.outputs.changed == 'true'
run: |
set -euo pipefail
echo "Writing updated metadata to ${TRACK_FILE}"
cp /tmp/upstream-runner.json "${TRACK_FILE}"
echo "Updated contents:"
cat "${TRACK_FILE}"
- name: Commit tracked metadata changes
if: steps.check.outputs.changed == 'true'
env:
UPSTREAM_VERSION: ${{ steps.check.outputs.upstream_version }}
UPSTREAM_COMMIT: ${{ steps.check.outputs.upstream_commit }}
run: |
set -euo pipefail
git config user.name "${GIT_CONFIG_USER_NAME}"
git config user.email "${GIT_CONFIG_USER_EMAIL}"
git add "${TRACK_FILE}"
if git diff --cached --quiet; then
echo "No tracked metadata changes to commit."
exit 0
fi
COMMIT_MSG="chore(ci): track actions/runner ${UPSTREAM_VERSION} (${UPSTREAM_COMMIT:0:7})"
echo "Committing: ${COMMIT_MSG}"
git commit -m "${COMMIT_MSG}"
- name: Push tracked metadata commit
if: steps.check.outputs.changed == 'true'
run: |
echo "Pushing commit to origin"
git push
echo "Push complete"
- name: Trigger downstream workflows
if: steps.check.outputs.changed == 'true' || (github.event_name == 'workflow_dispatch' && inputs.force_publish)
env:
GH_TOKEN: ${{ github.token }}
REPO: ${{ github.repository }}
DEFAULT_BRANCH: ${{ github.event.repository.default_branch }}
run: |
set -euo pipefail
dispatch() {
local workflow="$1"
echo "Dispatching ${workflow} on ${DEFAULT_BRANCH}"
curl -fsSL -X POST \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer ${GH_TOKEN}" \
"https://api.github.com/repos/${REPO}/actions/workflows/${workflow}/dispatches" \
-d "{\"ref\":\"${DEFAULT_BRANCH}\"}"
echo "Dispatch sent: ${workflow}"
}
dispatch "${TARGET_WORKFLOW_PUBLISH}"
dispatch "${TARGET_WORKFLOW_RELEASE}"
echo "All downstream workflows dispatched"
- name: Publish monitor summary
if: always()
env:
CHANGED: ${{ steps.check.outputs.changed }}
UPSTREAM_VERSION: ${{ steps.check.outputs.upstream_version }}
UPSTREAM_COMMIT: ${{ steps.check.outputs.upstream_commit }}
UPSTREAM_DATE: ${{ steps.check.outputs.upstream_date }}
EVENT_NAME: ${{ github.event_name }}
FORCE_PUBLISH: ${{ inputs.force_publish }}
run: |
changed="${CHANGED:-false}"
force="${FORCE_PUBLISH:-false}"
triggered=false
trigger_reason=""
if [ "${changed}" = "true" ]; then
triggered=true
trigger_reason="upstream metadata changed"
elif [ "${EVENT_NAME}" = "workflow_dispatch" ] && [ "${force}" = "true" ]; then
triggered=true
trigger_reason="force_publish requested via workflow_dispatch"
fi
{
echo "## Upstream actions/runner Monitor"
echo ""
echo "### Upstream"
echo "| Field | Value |"
echo "| --- | --- |"
echo "| Repo | [${UPSTREAM_REPO}](https://github.com/${UPSTREAM_REPO}) |"
echo "| Version | \`${UPSTREAM_VERSION:-unknown}\` |"
echo "| Commit | \`${UPSTREAM_COMMIT:-unknown}\` |"
echo "| Published | \`${UPSTREAM_DATE:-unknown}\` |"
echo ""
echo "### Run"
echo "| Field | Value |"
echo "| --- | --- |"
echo "| Trigger | \`${EVENT_NAME}\` |"
if [ "${changed}" = "true" ]; then
echo "| Upstream changed | Yes — metadata updated and committed |"
else
echo "| Upstream changed | No — metadata unchanged |"
fi
if [ "${triggered}" = "true" ]; then
echo "| Downstream triggered | Yes — ${trigger_reason} |"
echo "| Workflows dispatched | \`${TARGET_WORKFLOW_PUBLISH}\`, \`${TARGET_WORKFLOW_RELEASE}\` |"
else
echo "| Downstream triggered | No — no change detected and force_publish not set |"
fi
} >> "$GITHUB_STEP_SUMMARY"