diff --git a/.github/actions-lock.txt b/.github/actions-lock.txt
index e4362d6..3f31d34 100644
--- a/.github/actions-lock.txt
+++ b/.github/actions-lock.txt
@@ -1,20 +1,20 @@
# SPDX-FileCopyrightText: 2025 Nextcloud GmbH and Nextcloud contributors
# SPDX-License-Identifier: MIT
e456e5920f7020b8fef59329ab6ce54e ai-policy.yml
-fe1239ed98a163abbdea3e0490c85458 appstore-build-publish.yml
-7f15fef2fde87aae0eb8386ded489372 command-compile.yml
-e6351c608939c31ae1e32923aa82aa10 dependabot-approve-merge.yml
+93826e24ee7f83d32dc39574505abc5a appstore-build-publish.yml
+87f8d9641dd087995de99f3da38ab23d command-compile.yml
+c1476a553c3223e70e49de980f22315e dependabot-approve-merge.yml
2581a67c5bcdcd570427e6d51db767d7 fixup.yml
-985f3ac7d51405c1601c742832a14120 lint-eslint.yml
+89736ea5a0440c90b73f5c722a456073 lint-eslint.yml
43fd0c5fb704cabc5f11cdfaf513236d lint-info-xml.yml
-4b40dd0073e16f74dd04e6d49dcc043d lint-php-cs.yml
-cfb31e47b6e9ab65e76c89b028754a4e lint-php.yml
-ab3a506506b1d7c1cea9593ecfd84366 lint-stylelint.yml
-aff9f466debc652013b43d1a11b32a0b npm-audit-fix.yml
-28dcf55e283b85c292fea0d0b2a15a8a npm-build.yml
-8fab08ac7da700ee304af0bf3c18b3a3 phpunit-mysql.yml
-43878db2acac51746332618c9f731553 psalm-matrix.yml
+79006ab196f5664fc444e63645cfd8a7 lint-php-cs.yml
+300be6a756abda800e40850918f2d964 lint-php.yml
+69ab1f99e6b290ca48c6ad916fd567cd lint-stylelint.yml
+9cd1e572898a8118b6df3fc47eeb3b8a npm-audit-fix.yml
+deb0d5cd79d29e8b73f689be32b4108d npm-build.yml
+3cacf28a710b387e83d3858af40b7ffe phpunit-mysql.yml
+6c355cb7b5d4da4d56a58e6d7f82881b psalm-matrix.yml
2dbec18233063b42f4d8e03bbb43671c reuse.yml
-94c65e30a77686c079c6dfa54a008440 sync-workflow-templates.yml
-a3440826636c0fd7c2d20b1de50363da update-nextcloud-ocp-approve-merge.yml
-7cc949cd51ea5d604986bbdcb75c95c7 update-nextcloud-ocp-matrix.yml
+511439ba27869e0324f283142cc8b3df sync-workflow-templates.yml
+abcb8206c3f6c5a9dc86cccf57846bfc update-nextcloud-ocp-approve-merge.yml
+ba78daa94b11b18fd0cf340160e5c776 update-nextcloud-ocp-matrix.yml
diff --git a/.github/workflows/appstore-build-publish.yml b/.github/workflows/appstore-build-publish.yml
index c0b6cde..27209c2 100644
--- a/.github/workflows/appstore-build-publish.yml
+++ b/.github/workflows/appstore-build-publish.yml
@@ -59,31 +59,29 @@ jobs:
expression: "//info//dependencies//nextcloud/@min-version"
- name: Read package.json node and npm engines version
- uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3
+ uses: nextcloud-libraries/parse-package-engines-action@122ae05d4257008180a514e1ddeb0c1b9d094bdd # v0.1.0
id: versions
# Continue if no package.json
continue-on-error: true
with:
- path: ${{ env.APP_NAME }}
- fallbackNode: '^24'
- fallbackNpm: '^11.3'
+ path: ${{ env.APP_NAME }}/package.json
- - name: Set up node ${{ steps.versions.outputs.nodeVersion }}
+ - name: Set up node ${{ steps.versions.outputs.node-version }}
# Skip if no package.json
- if: ${{ steps.versions.outputs.nodeVersion }}
+ if: ${{ steps.versions.outcome == 'success' }}
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
- node-version: ${{ steps.versions.outputs.nodeVersion }}
+ node-version: ${{ steps.versions.outputs.node-version }}
package-manager-cache: false
- - name: Set up npm ${{ steps.versions.outputs.npmVersion }}
+ - name: Set up npm ${{ steps.versions.outputs.package-manager-version }}
# Skip if no package.json
- if: ${{ steps.versions.outputs.npmVersion }}
- run: npm i -g 'npm@${{ steps.versions.outputs.npmVersion }}'
+ if: ${{ steps.versions.outcome == 'success' }}
+ run: npm i -g 'npm@${{ steps.versions.outputs.package-manager-version }}'
- name: Get php version
id: php-versions
- uses: icewind1991/nextcloud-version-matrix@8a7bac6300b2f0f3100088b297995a229558ddba # v1.3.2
+ uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3
with:
filename: ${{ env.APP_NAME }}/appinfo/info.xml
@@ -111,7 +109,7 @@ jobs:
- name: Build ${{ env.APP_NAME }}
# Skip if no package.json
- if: ${{ steps.versions.outputs.nodeVersion }}
+ if: ${{ steps.versions.outcome == 'success' }}
env:
CYPRESS_INSTALL_BINARY: 0
run: |
@@ -194,7 +192,7 @@ jobs:
overwrite: true
- name: Upload app to Nextcloud appstore
- uses: nextcloud-releases/nextcloud-appstore-push-action@a011fe619bcf6e77ddebc96f9908e1af4071b9c1 # v1.0.3
+ uses: nextcloud-libraries/nextcloud-appstore-push-action@a011fe619bcf6e77ddebc96f9908e1af4071b9c1 # v1.0.3
with:
app_name: ${{ env.APP_NAME }}
appstore_token: ${{ secrets.APPSTORE_TOKEN }}
diff --git a/.github/workflows/command-compile.yml b/.github/workflows/command-compile.yml
index 3b33c04..a6809f7 100644
--- a/.github/workflows/command-compile.yml
+++ b/.github/workflows/command-compile.yml
@@ -116,20 +116,17 @@ jobs:
git config --local user.name 'nextcloud-command'
- name: Read package.json node and npm engines version
- uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3
+ uses: nextcloud-libraries/parse-package-engines-action@122ae05d4257008180a514e1ddeb0c1b9d094bdd # v0.1.0
id: package-engines-versions
- with:
- fallbackNode: '^24'
- fallbackNpm: '^11.3'
- - name: Set up node ${{ steps.package-engines-versions.outputs.nodeVersion }}
+ - name: Set up node ${{ steps.package-engines-versions.outputs.node-version }}
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
- node-version: ${{ steps.package-engines-versions.outputs.nodeVersion }}
+ node-version: ${{ steps.package-engines-versions.outputs.node-version }}
cache: npm
- - name: Set up npm ${{ steps.package-engines-versions.outputs.npmVersion }}
- run: npm i -g 'npm@${{ steps.package-engines-versions.outputs.npmVersion }}'
+ - name: Set up npm ${{ steps.package-engines-versions.outputs.package-manager-version }}
+ run: npm i -g 'npm@${{ steps.package-engines-versions.outputs.package-manager-version }}'
- name: Rebase to ${{ needs.init.outputs.base_ref }}
if: ${{ contains(needs.init.outputs.arg1, 'rebase') }}
diff --git a/.github/workflows/dependabot-approve-merge.yml b/.github/workflows/dependabot-approve-merge.yml
index 76340ac..eaa1e9f 100644
--- a/.github/workflows/dependabot-approve-merge.yml
+++ b/.github/workflows/dependabot-approve-merge.yml
@@ -9,7 +9,7 @@
name: Auto approve Dependabot PRs
on:
- pull_request_target: # zizmor: ignore[dangerous-triggers]
+ pull_request:
branches:
- main
- master
diff --git a/.github/workflows/lint-eslint.yml b/.github/workflows/lint-eslint.yml
index f84f276..43ef34c 100644
--- a/.github/workflows/lint-eslint.yml
+++ b/.github/workflows/lint-eslint.yml
@@ -28,7 +28,7 @@ jobs:
src: ${{ steps.changes.outputs.src}}
steps:
- - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2
+ - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3
id: changes
continue-on-error: true
with:
@@ -61,19 +61,16 @@ jobs:
persist-credentials: false
- name: Read package.json node and npm engines version
- uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3
+ uses: nextcloud-libraries/parse-package-engines-action@122ae05d4257008180a514e1ddeb0c1b9d094bdd # v0.1.0
id: versions
- with:
- fallbackNode: '^24'
- fallbackNpm: '^11.3'
- - name: Set up node ${{ steps.versions.outputs.nodeVersion }}
+ - name: Set up node ${{ steps.versions.outputs.node-version }}
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
- node-version: ${{ steps.versions.outputs.nodeVersion }}
+ node-version: ${{ steps.versions.outputs.node-version }}
- - name: Set up npm ${{ steps.versions.outputs.npmVersion }}
- run: npm i -g 'npm@${{ steps.versions.outputs.npmVersion }}'
+ - name: Set up npm ${{ steps.versions.outputs.package-manager-version }}
+ run: npm i -g 'npm@${{ steps.versions.outputs.package-manager-version }}'
- name: Install dependencies
env:
diff --git a/.github/workflows/lint-php-cs.yml b/.github/workflows/lint-php-cs.yml
index dba0956..06d0842 100644
--- a/.github/workflows/lint-php-cs.yml
+++ b/.github/workflows/lint-php-cs.yml
@@ -31,7 +31,7 @@ jobs:
- name: Get php version
id: versions
- uses: icewind1991/nextcloud-version-matrix@8a7bac6300b2f0f3100088b297995a229558ddba # v1.3.2
+ uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3
- name: Set up php${{ steps.versions.outputs.php-min }}
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
diff --git a/.github/workflows/lint-php.yml b/.github/workflows/lint-php.yml
index e73949e..e4c6e9b 100644
--- a/.github/workflows/lint-php.yml
+++ b/.github/workflows/lint-php.yml
@@ -31,7 +31,7 @@ jobs:
- name: Get version matrix
id: versions
- uses: icewind1991/nextcloud-version-matrix@8a7bac6300b2f0f3100088b297995a229558ddba # v1.3.2
+ uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3
php-lint:
runs-on: ubuntu-latest-low
diff --git a/.github/workflows/lint-stylelint.yml b/.github/workflows/lint-stylelint.yml
index e4b26b5..f648d41 100644
--- a/.github/workflows/lint-stylelint.yml
+++ b/.github/workflows/lint-stylelint.yml
@@ -30,19 +30,16 @@ jobs:
persist-credentials: false
- name: Read package.json node and npm engines version
- uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3
+ uses: nextcloud-libraries/parse-package-engines-action@122ae05d4257008180a514e1ddeb0c1b9d094bdd # v0.1.0
id: versions
- with:
- fallbackNode: '^24'
- fallbackNpm: '^11.3'
- - name: Set up node ${{ steps.versions.outputs.nodeVersion }}
+ - name: Set up node ${{ steps.versions.outputs.node-version }}
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
- node-version: ${{ steps.versions.outputs.nodeVersion }}
+ node-version: ${{ steps.versions.outputs.node-version }}
- - name: Set up npm ${{ steps.versions.outputs.npmVersion }}
- run: npm i -g 'npm@${{ steps.versions.outputs.npmVersion }}'
+ - name: Set up npm ${{ steps.versions.outputs.package-manager-version }}
+ run: npm i -g 'npm@${{ steps.versions.outputs.package-manager-version }}'
- name: Install dependencies
env:
diff --git a/.github/workflows/npm-audit-fix.yml b/.github/workflows/npm-audit-fix.yml
index 928fc93..338e5f5 100644
--- a/.github/workflows/npm-audit-fix.yml
+++ b/.github/workflows/npm-audit-fix.yml
@@ -15,20 +15,25 @@ on:
- cron: '30 2 * * 0'
permissions:
- contents: read
+ contents: write
+ pull-requests: write
jobs:
build:
runs-on: ubuntu-latest
+ env:
+ # env variable for maintainers: 'false' disables auto-merge for these pull requests
+ AUTOMERGE: true
+
strategy:
fail-fast: false
matrix:
branches:
- ${{ github.event.repository.default_branch }}
+ - 'stable35'
- 'stable34'
- 'stable33'
- - 'stable32'
name: npm-audit-fix-${{ matrix.branches }}
@@ -42,19 +47,16 @@ jobs:
continue-on-error: true
- name: Read package.json node and npm engines version
- uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3
+ uses: nextcloud-libraries/parse-package-engines-action@122ae05d4257008180a514e1ddeb0c1b9d094bdd # v0.1.0
id: versions
- with:
- fallbackNode: '^24'
- fallbackNpm: '^11.3'
- - name: Set up node ${{ steps.versions.outputs.nodeVersion }}
+ - name: Set up node ${{ steps.versions.outputs.node-version }}
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
- node-version: ${{ steps.versions.outputs.nodeVersion }}
+ node-version: ${{ steps.versions.outputs.node-version }}
- - name: Set up npm ${{ steps.versions.outputs.npmVersion }}
- run: npm i -g 'npm@${{ steps.versions.outputs.npmVersion }}'
+ - name: Set up npm ${{ steps.versions.outputs.package-manager-version }}
+ run: npm i -g 'npm@${{ steps.versions.outputs.package-manager-version }}'
- name: Fix npm audit
id: npm-audit
@@ -69,6 +71,7 @@ jobs:
npm run build --if-present
- name: Create Pull Request
+ id: create-pull-request
if: steps.checkout.outcome == 'success'
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
@@ -83,3 +86,19 @@ jobs:
labels: |
dependencies
3. to review
+
+ # Approve using the default GITHUB_TOKEN, as the PR itself was created
+ # using COMMAND_BOT_PAT and GitHub does not allow an account to approve its own PR
+ - name: GitHub actions bot approve
+ if: steps.create-pull-request.outputs.pull-request-operation != 'none'
+ run: gh pr review --approve "$PR_URL"
+ env:
+ PR_URL: ${{ steps.create-pull-request.outputs.pull-request-url }}
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+
+ - name: Enable auto merge
+ if: steps.create-pull-request.outputs.pull-request-operation != 'none' && fromJSON(env.AUTOMERGE)
+ uses: peter-evans/enable-pull-request-automerge@a660677d5469627102a1c1e11409dd063606628d # v3.0.0
+ with:
+ token: ${{ secrets.GITHUB_TOKEN }}
+ pull-request-number: ${{ steps.create-pull-request.outputs.pull-request-number }}
diff --git a/.github/workflows/npm-build.yml b/.github/workflows/npm-build.yml
index 1b9e372..f81723b 100644
--- a/.github/workflows/npm-build.yml
+++ b/.github/workflows/npm-build.yml
@@ -28,7 +28,7 @@ jobs:
src: ${{ steps.changes.outputs.src}}
steps:
- - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2
+ - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3
id: changes
continue-on-error: true
with:
@@ -58,19 +58,16 @@ jobs:
persist-credentials: false
- name: Read package.json node and npm engines version
- uses: skjnldsv/read-package-engines-version-actions@06d6baf7d8f41934ab630e97d9e6c0bc9c9ac5e4 # v3
+ uses: nextcloud-libraries/parse-package-engines-action@122ae05d4257008180a514e1ddeb0c1b9d094bdd # v0.1.0
id: versions
- with:
- fallbackNode: '^24'
- fallbackNpm: '^11.3'
- - name: Set up node ${{ steps.versions.outputs.nodeVersion }}
+ - name: Set up node ${{ steps.versions.outputs.node-version }}
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
- node-version: ${{ steps.versions.outputs.nodeVersion }}
+ node-version: ${{ steps.versions.outputs.node-version }}
- - name: Set up npm ${{ steps.versions.outputs.npmVersion }}
- run: npm i -g 'npm@${{ steps.versions.outputs.npmVersion }}'
+ - name: Set up npm ${{ steps.versions.outputs.package-manager-version }}
+ run: npm i -g 'npm@${{ steps.versions.outputs.package-manager-version }}'
- name: Validate package-lock.json # See https://github.com/npm/cli/issues/4460
run: |
diff --git a/.github/workflows/phpunit-mysql.yml b/.github/workflows/phpunit-mysql.yml
index 40f41ae..a7d98c9 100644
--- a/.github/workflows/phpunit-mysql.yml
+++ b/.github/workflows/phpunit-mysql.yml
@@ -18,33 +18,18 @@ concurrency:
cancel-in-progress: true
jobs:
- matrix:
- runs-on: ubuntu-latest-low
- outputs:
- matrix: ${{ steps.versions.outputs.sparse-matrix }}
- steps:
- - name: Checkout app
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- with:
- persist-credentials: false
-
- - name: Get version matrix
- id: versions
- uses: icewind1991/nextcloud-version-matrix@8a7bac6300b2f0f3100088b297995a229558ddba # v1.3.2
- with:
- matrix: '{"mysql-versions": ["8.4"]}'
-
- changes:
+ changes-and-matrix:
runs-on: ubuntu-latest-low
permissions:
contents: read
pull-requests: read
outputs:
- src: ${{ steps.changes.outputs.src}}
+ src: ${{ steps.changes.outputs.src }}
+ matrix: ${{ steps.versions.outputs.sparse-matrix }}
steps:
- - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2
+ - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3
id: changes
continue-on-error: true
with:
@@ -61,15 +46,28 @@ jobs:
- 'composer.json'
- 'composer.lock'
+ - name: Checkout app
+ if: steps.changes.outputs.src != 'false'
+ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
+ with:
+ persist-credentials: false
+
+ - name: Get version matrix
+ if: steps.changes.outputs.src != 'false'
+ id: versions
+ uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3
+ with:
+ matrix: '{"mysql-versions": ["8.4"]}'
+
phpunit-mysql:
runs-on: ubuntu-latest
- needs: [changes, matrix]
- if: needs.changes.outputs.src != 'false'
+ needs: changes-and-matrix
+ if: needs.changes-and-matrix.outputs.src != 'false'
strategy:
fail-fast: false
- matrix: ${{ fromJson(needs.matrix.outputs.matrix) }}
+ matrix: ${{ fromJson(needs.changes-and-matrix.outputs.matrix) }}
name: MySQL ${{ matrix.mysql-versions }} PHP ${{ matrix.php-versions }} Nextcloud ${{ matrix.server-versions }}
@@ -194,7 +192,7 @@ jobs:
permissions:
contents: none
runs-on: ubuntu-latest-low
- needs: [changes, phpunit-mysql]
+ needs: [changes-and-matrix, phpunit-mysql]
if: always()
@@ -202,4 +200,4 @@ jobs:
steps:
- name: Summary status
- run: if ${{ needs.changes.outputs.src != 'false' && needs.phpunit-mysql.result != 'success' }}; then exit 1; fi
+ run: if ${{ needs.changes-and-matrix.outputs.src != 'false' && needs.phpunit-mysql.result != 'success' }}; then exit 1; fi
diff --git a/.github/workflows/psalm-matrix.yml b/.github/workflows/psalm-matrix.yml
index a2e09e8..3fa1abf 100644
--- a/.github/workflows/psalm-matrix.yml
+++ b/.github/workflows/psalm-matrix.yml
@@ -31,7 +31,7 @@ jobs:
- name: Get version matrix
id: versions
- uses: icewind1991/nextcloud-version-matrix@8a7bac6300b2f0f3100088b297995a229558ddba # v1.3.2
+ uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3
- name: Check enforcement of minimum PHP version ${{ steps.versions.outputs.php-min }} in psalm.xml
run: grep 'phpVersion="${{ steps.versions.outputs.php-min }}' psalm.xml
diff --git a/.github/workflows/sync-workflow-templates.yml b/.github/workflows/sync-workflow-templates.yml
index 0e925bb..40d39e1 100644
--- a/.github/workflows/sync-workflow-templates.yml
+++ b/.github/workflows/sync-workflow-templates.yml
@@ -26,9 +26,9 @@ jobs:
matrix:
branches:
- ${{ github.event.repository.default_branch }}
+ - 'stable35'
- 'stable34'
- 'stable33'
- - 'stable32'
name: Update workflows in ${{ matrix.branches }}
diff --git a/.github/workflows/update-nextcloud-ocp-approve-merge.yml b/.github/workflows/update-nextcloud-ocp-approve-merge.yml
index 88c54da..4d9f82a 100644
--- a/.github/workflows/update-nextcloud-ocp-approve-merge.yml
+++ b/.github/workflows/update-nextcloud-ocp-approve-merge.yml
@@ -6,17 +6,14 @@
# SPDX-FileCopyrightText: 2023-2024 Nextcloud GmbH and Nextcloud contributors
# SPDX-License-Identifier: MIT
-name: Auto approve nextcloud/ocp
+# TODO: Remove this after a grace period of 6 months to give everyone the chance to remove the workflow
+# TODO: To be removed mid 2027.
+name: No-op please remove this workflow
-on:
- pull_request_target: # zizmor: ignore[dangerous-triggers]
- branches:
- - main
- - master
- - stable*
+on: pull_request
permissions:
- contents: read
+ contents: none
concurrency:
group: update-nextcloud-ocp-approve-merge-${{ github.head_ref || github.run_id }}
@@ -24,36 +21,12 @@ concurrency:
jobs:
auto-approve-merge:
- if: github.actor == 'nextcloud-command'
runs-on: ubuntu-latest-low
- permissions:
- # for auto-approve-action to approve PRs
- pull-requests: write
- # for alexwilson/enable-github-automerge-action to approve PRs
- contents: write
+ if: always()
- steps:
- - name: Disabled on forks
- if: ${{ github.event.pull_request.head.repo.full_name != github.repository }}
- run: |
- echo 'Can not approve PRs from forks'
- exit 1
-
- - uses: mdecoleman/pr-branch-name@55795d86b4566d300d237883103f052125cc7508 # v3.0.0
- id: branchname
- with:
- repo-token: ${{ secrets.GITHUB_TOKEN }}
+ # This is the summary, we just avoid to rename it so that branch protection rules still match
+ name: auto-approve-merge
- - name: GitHub actions bot approve
- if: startsWith(steps.branchname.outputs.branch, 'automated/noid/') && endsWith(steps.branchname.outputs.branch, 'update-nextcloud-ocp')
- run: gh pr review --approve "$PR_URL"
- env:
- PR_URL: ${{ github.event.pull_request.html_url }}
- GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
-
- # Enable GitHub auto merge
- - name: Auto merge
- uses: alexwilson/enable-github-automerge-action@2c32e18a76e0726ffe7a573bfff2d42a20885126 # 3.0.0
- if: startsWith(steps.branchname.outputs.branch, 'automated/noid/') && endsWith(steps.branchname.outputs.branch, 'update-nextcloud-ocp')
- with:
- github-token: ${{ secrets.GITHUB_TOKEN }}
+ steps:
+ - name: No-op please remove this workflow
+ run: echo "Approve and auto-merge has been folded into update-nextcloud-ocp.yml / update-nextcloud-ocp-matrix.yml, please remove this file"; exit 1;
diff --git a/.github/workflows/update-nextcloud-ocp-matrix.yml b/.github/workflows/update-nextcloud-ocp-matrix.yml
index 4972327..cbb7005 100644
--- a/.github/workflows/update-nextcloud-ocp-matrix.yml
+++ b/.github/workflows/update-nextcloud-ocp-matrix.yml
@@ -14,8 +14,9 @@ on:
- cron: '5 2 * * 0'
permissions:
- contents: read
+ contents: write
issues: write
+ pull-requests: write
jobs:
update-nextcloud-ocp:
@@ -24,6 +25,10 @@ jobs:
# Only allowed to be run on nextcloud repositories
if: ${{ github.repository_owner == 'nextcloud' }}
+ env:
+ # env variable for maintainers: 'false' disables auto-merge for these pull requests
+ AUTOMERGE: true
+
strategy:
fail-fast: false
matrix:
@@ -41,7 +46,7 @@ jobs:
- name: Get version matrix
id: versions
- uses: icewind1991/nextcloud-version-matrix@8a7bac6300b2f0f3100088b297995a229558ddba # v1.3.2
+ uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3
- name: Set up php8.3
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
@@ -91,6 +96,7 @@ jobs:
body: 'Please check the output of the GitHub action and manually resolve the issues
${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
${{ steps.codeowners.outputs.codeowners }}'
- name: Create Pull Request
+ id: create-pull-request
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
token: ${{ secrets.COMMAND_BOT_PAT }}
@@ -100,13 +106,25 @@ jobs:
signoff: true
branch: 'automated/noid/${{ matrix.branches }}-update-nextcloud-ocp'
title: '[${{ matrix.branches }}] Update nextcloud/ocp dependency'
- add-path: |
- composer.json
- composer.lock
- vendor-bin/nextcloud-ocp/composer.json
- vendor-bin/nextcloud-ocp/composer.lock
+ add-paths: ${{ steps.check_composer_bin.outputs.files_exists == 'true' && 'vendor-bin/nextcloud-ocp/composer.json,vendor-bin/nextcloud-ocp/composer.lock' || 'composer.json,composer.lock' }}
body: |
Auto-generated update of [nextcloud/ocp](https://github.com/nextcloud-deps/ocp/) dependency
labels: |
dependencies
3. to review
+
+ # Approve using the default GITHUB_TOKEN, as the PR itself was created
+ # using COMMAND_BOT_PAT and GitHub does not allow an account to approve its own PR
+ - name: GitHub actions bot approve
+ if: steps.create-pull-request.outputs.pull-request-operation != 'none'
+ run: gh pr review --approve "$PR_URL"
+ env:
+ PR_URL: ${{ steps.create-pull-request.outputs.pull-request-url }}
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+
+ - name: Enable auto merge
+ if: steps.create-pull-request.outputs.pull-request-operation != 'none' && fromJSON(env.AUTOMERGE)
+ uses: peter-evans/enable-pull-request-automerge@a660677d5469627102a1c1e11409dd063606628d # v3.0.0
+ with:
+ token: ${{ secrets.GITHUB_TOKEN }}
+ pull-request-number: ${{ steps.create-pull-request.outputs.pull-request-number }}