diff --git a/.github/actions-lock.txt b/.github/actions-lock.txt
index d0cea93..6b13d86 100644
--- a/.github/actions-lock.txt
+++ b/.github/actions-lock.txt
@@ -18,7 +18,6 @@ aaa395a26591445ccf4c8196d7f01ee7 pr-feedback.yml
6c355cb7b5d4da4d56a58e6d7f82881b psalm-matrix.yml
2dbec18233063b42f4d8e03bbb43671c reuse.yml
b47a9fe981a7435caea92db33f5ad121 sync-workflow-templates.yml
-a3440826636c0fd7c2d20b1de50363da update-nextcloud-ocp-approve-merge.yml
5136d37752a491c7ed2071b9241b94fd update-nextcloud-ocp-matrix.yml
22604c31b526de270a080eb19967a638 update-stable-titles.yml
ab958fa2b07234fceab6b6d836fb7f19 npm-build.yml
diff --git a/.github/workflows/npm-audit-fix.yml b/.github/workflows/npm-audit-fix.yml
index fd84e64..b9403d5 100644
--- a/.github/workflows/npm-audit-fix.yml
+++ b/.github/workflows/npm-audit-fix.yml
@@ -15,12 +15,17 @@ on:
- cron: '30 2 * * 0'
permissions:
- contents: read
+ contents: write
+ pull-requests: write
jobs:
build:
runs-on: ubuntu-latest
+ env:
+ # env variable for maintainers: 'false' disables auto-merge for these pull requests
+ AUTOMERGE: true
+
strategy:
fail-fast: false
matrix:
@@ -29,7 +34,6 @@ jobs:
- 'stable35'
- 'stable34'
- 'stable33'
- - 'stable32'
name: npm-audit-fix-${{ matrix.branches }}
@@ -70,6 +74,7 @@ jobs:
npm run build --if-present
- name: Create Pull Request
+ id: create-pull-request
if: steps.checkout.outcome == 'success'
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
@@ -84,3 +89,19 @@ jobs:
labels: |
dependencies
3. to review
+
+ # Approve using the default GITHUB_TOKEN, as the PR itself was created
+ # using COMMAND_BOT_PAT and GitHub does not allow an account to approve its own PR
+ - name: GitHub actions bot approve
+ if: steps.create-pull-request.outputs.pull-request-operation != 'none'
+ run: gh pr review --approve "$PR_URL"
+ env:
+ PR_URL: ${{ steps.create-pull-request.outputs.pull-request-url }}
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+
+ - name: Enable auto merge
+ if: steps.create-pull-request.outputs.pull-request-operation != 'none' && fromJSON(env.AUTOMERGE)
+ uses: peter-evans/enable-pull-request-automerge@a660677d5469627102a1c1e11409dd063606628d # v3.0.0
+ with:
+ token: ${{ secrets.GITHUB_TOKEN }}
+ pull-request-number: ${{ steps.create-pull-request.outputs.pull-request-number }}
diff --git a/.github/workflows/update-nextcloud-ocp-approve-merge.yml b/.github/workflows/update-nextcloud-ocp-approve-merge.yml
deleted file mode 100644
index 88c54da..0000000
--- a/.github/workflows/update-nextcloud-ocp-approve-merge.yml
+++ /dev/null
@@ -1,59 +0,0 @@
-# This workflow is provided via the organization template repository
-#
-# https://github.com/nextcloud/.github
-# https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization
-#
-# SPDX-FileCopyrightText: 2023-2024 Nextcloud GmbH and Nextcloud contributors
-# SPDX-License-Identifier: MIT
-
-name: Auto approve nextcloud/ocp
-
-on:
- pull_request_target: # zizmor: ignore[dangerous-triggers]
- branches:
- - main
- - master
- - stable*
-
-permissions:
- contents: read
-
-concurrency:
- group: update-nextcloud-ocp-approve-merge-${{ github.head_ref || github.run_id }}
- cancel-in-progress: true
-
-jobs:
- auto-approve-merge:
- if: github.actor == 'nextcloud-command'
- runs-on: ubuntu-latest-low
- permissions:
- # for auto-approve-action to approve PRs
- pull-requests: write
- # for alexwilson/enable-github-automerge-action to approve PRs
- contents: write
-
- steps:
- - name: Disabled on forks
- if: ${{ github.event.pull_request.head.repo.full_name != github.repository }}
- run: |
- echo 'Can not approve PRs from forks'
- exit 1
-
- - uses: mdecoleman/pr-branch-name@55795d86b4566d300d237883103f052125cc7508 # v3.0.0
- id: branchname
- with:
- repo-token: ${{ secrets.GITHUB_TOKEN }}
-
- - name: GitHub actions bot approve
- if: startsWith(steps.branchname.outputs.branch, 'automated/noid/') && endsWith(steps.branchname.outputs.branch, 'update-nextcloud-ocp')
- run: gh pr review --approve "$PR_URL"
- env:
- PR_URL: ${{ github.event.pull_request.html_url }}
- GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
-
- # Enable GitHub auto merge
- - name: Auto merge
- uses: alexwilson/enable-github-automerge-action@2c32e18a76e0726ffe7a573bfff2d42a20885126 # 3.0.0
- if: startsWith(steps.branchname.outputs.branch, 'automated/noid/') && endsWith(steps.branchname.outputs.branch, 'update-nextcloud-ocp')
- with:
- github-token: ${{ secrets.GITHUB_TOKEN }}
diff --git a/.github/workflows/update-nextcloud-ocp-matrix.yml b/.github/workflows/update-nextcloud-ocp-matrix.yml
index 376fdc5..92e48ef 100644
--- a/.github/workflows/update-nextcloud-ocp-matrix.yml
+++ b/.github/workflows/update-nextcloud-ocp-matrix.yml
@@ -14,8 +14,9 @@ on:
- cron: '5 2 * * 0'
permissions:
- contents: read
+ contents: write
issues: write
+ pull-requests: write
jobs:
update-nextcloud-ocp:
@@ -24,6 +25,10 @@ jobs:
# Only allowed to be run on nextcloud repositories
if: ${{ github.repository_owner == 'nextcloud' }}
+ env:
+ # env variable for maintainers: 'false' disables auto-merge for these pull requests
+ AUTOMERGE: true
+
strategy:
fail-fast: false
matrix:
@@ -91,6 +96,7 @@ jobs:
body: 'Please check the output of the GitHub action and manually resolve the issues
${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
${{ steps.codeowners.outputs.codeowners }}'
- name: Create Pull Request
+ id: create-pull-request
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
token: ${{ secrets.COMMAND_BOT_PAT }}
@@ -110,3 +116,19 @@ jobs:
labels: |
dependencies
3. to review
+
+ # Approve using the default GITHUB_TOKEN, as the PR itself was created
+ # using COMMAND_BOT_PAT and GitHub does not allow an account to approve its own PR
+ - name: GitHub actions bot approve
+ if: steps.create-pull-request.outputs.pull-request-operation != 'none'
+ run: gh pr review --approve "$PR_URL"
+ env:
+ PR_URL: ${{ steps.create-pull-request.outputs.pull-request-url }}
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+
+ - name: Enable auto merge
+ if: steps.create-pull-request.outputs.pull-request-operation != 'none' && fromJSON(env.AUTOMERGE)
+ uses: peter-evans/enable-pull-request-automerge@a660677d5469627102a1c1e11409dd063606628d # v3.0.0
+ with:
+ token: ${{ secrets.GITHUB_TOKEN }}
+ pull-request-number: ${{ steps.create-pull-request.outputs.pull-request-number }}