Build using CI and restrict commits by users (#924)

This commit is contained in:
Robin Raju authored and GitHub committed 2026-04-07 00:04:53 +01:00
1 parent 1f7f974dea
commit a932998710
5 files changed
+100 -65

No files matched your search

+61 -46
View File
@@ -1,75 +1,90 @@
# In TypeScript actions, `dist/` is a special directory. When you reference
# an action with the `uses:` property, `dist/index.js` is the code that will be
# run. For this project, the `dist/index.js` file is transpiled from other
# source files. This workflow ensures the `dist/` directory contains the
# expected transpiled code.
#
# If this workflow is run from a feature branch, it will act as an additional CI
# check and fail if the checked-in `dist/` directory does not match what is
# expected from the build.
name: Check Transpiled JavaScript
name: Update dist
on:
pull_request:
branches:
- main
push:
workflow_run:
workflows:
- Build and Test
types:
- completed
branches:
- main
permissions:
contents: read
concurrency:
group: update-dist-main
cancel-in-progress: false
jobs:
check-dist:
name: Check dist/
publish-dist:
if: >-
${{
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push'
}}
name: Publish dist
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Checkout
id: checkout
- name: Checkout main
uses: actions/checkout@v6
with:
ref: main
fetch-depth: 0
- name: Ensure main is still at the validated commit
id: tip-check
shell: bash
run: |
current_head="$(git rev-parse HEAD)"
validated_head="${{ github.event.workflow_run.head_sha }}"
if [ "$current_head" = "$validated_head" ]; then
echo "publish=true" >> "$GITHUB_OUTPUT"
exit 0
fi
echo "publish=false" >> "$GITHUB_OUTPUT"
echo "main moved from $validated_head to $current_head; a newer successful Build and Test run will refresh dist."
- name: Setup Node.js
id: setup-node
if: steps.tip-check.outputs.publish == 'true'
uses: actions/setup-node@v6
with:
node-version-file: '.node-version'
cache: npm
- name: Install Dependencies
id: install
- name: Install dependencies
if: steps.tip-check.outputs.publish == 'true'
run: npm ci
- name: Build dist/ Directory
id: build
- name: Build dist
if: steps.tip-check.outputs.publish == 'true'
run: npm run package
# This will fail the workflow if the `dist/` directory is different than
# expected.
- name: Compare Directories
id: diff
- name: Detect dist changes
if: steps.tip-check.outputs.publish == 'true'
id: dist-status
shell: bash
run: |
if [ ! -d dist/ ]; then
echo "Expected dist/ directory does not exist. See status below:"
ls -la ./
exit 1
fi
if ! git diff --ignore-space-at-eol --text --quiet -- dist/ || \
if ! git diff --quiet -- dist/ || \
[ -n "$(git ls-files --others --exclude-standard -- dist/)" ]; then
echo "Detected uncommitted changes after build. See status below:"
echo "changed=true" >> "$GITHUB_OUTPUT"
git --no-pager status --short -- dist/
git --no-pager diff --ignore-space-at-eol --text -- dist/
exit 1
exit 0
fi
# If `dist/` was different than expected, upload the expected version as a
# workflow artifact.
- if: ${{ failure() && steps.diff.outcome == 'failure' }}
name: Upload Artifact
id: upload
uses: actions/upload-artifact@v6
with:
name: dist
path: dist/
echo "changed=false" >> "$GITHUB_OUTPUT"
- name: Commit refreshed dist
if: steps.dist-status.outputs.changed == 'true'
shell: bash
run: |
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add dist/
git commit -m "chore: refresh dist [skip ci]"
git push origin HEAD:main
+6
View File
@@ -16,6 +16,12 @@ env:
jobs:
build:
if: >-
${{
github.ref != 'refs/heads/main' ||
github.actor != 'github-actions[bot]' ||
!contains(github.event.head_commit.message, '[skip ci]')
}}
strategy:
fail-fast: false
matrix:
+14
View File
@@ -20,6 +20,20 @@ jobs:
steps:
- name: Checkout Repo
uses: actions/checkout@v6
with:
fetch-depth: 0
- name: Reject committed dist changes
shell: bash
run: |
dist_changes="$(git diff --name-only "${{ github.event.pull_request.base.sha }}"..HEAD -- dist)"
if [ -n "$dist_changes" ]; then
echo "dist/ is CI-managed and must not be changed in pull requests."
echo "Changed dist files:"
echo "$dist_changes"
exit 1
fi
- name: Setup node and cache dependencies
uses: actions/setup-node@v6
+13 -19
View File
@@ -11,14 +11,19 @@ Install dependencies
npm install
```
Build the distributable bundle and refresh the checked-in `dist/` output
Build the distributable bundle locally when you need to exercise the action from
this checkout
```bash
npm run package
```
If you change runtime code under `src/`, run `npm run package` and commit the
updated `dist/` contents. CI verifies that the committed bundle stays in sync.
`dist/` is CI-managed. Pull requests must not include `dist/` changes; PR
validation rejects them, and a post-merge workflow rebuilds and commits the
generated bundle back to `main`.
If you only needed a local bundle for debugging, discard the generated `dist/`
changes before committing.
Run tests :heavy_check_mark:
@@ -72,23 +77,12 @@ See the
[toolkit documentation](https://github.com/actions/toolkit/blob/master/README.md#packages)
for the various packages.
## Publish to a distribution branch
## Dist publication
Actions are run from GitHub repos so we will checkin the packed dist folder.
Then run [ncc](https://github.com/zeit/ncc) and push the results:
```bash
$ npm run package
$ git add dist
$ git commit -a -m "prod dependencies"
$ git push origin releases/v1
```
Your action is now published! :rocket:
See the
[versioning documentation](https://github.com/actions/toolkit/blob/master/docs/action-versioning.md)
This repository keeps `dist/` in Git because `action.yml` points to
`dist/index.js`, but contributors do not publish it manually. After a change
lands on `main`, GitHub Actions rebuilds `dist/` and commits the generated
bundle back to the branch with the Actions bot.
## Validate
+6
View File
@@ -184,3 +184,9 @@ ${{steps.<step-id>.outputs.tag_name}}
latest: true
preRelease: true
```
## Development notes
`dist/` is CI-managed for this repository. Pull requests should include source,
tests, and workflow changes only; after a merge to `main`, GitHub Actions
rebuilds `dist/` and commits the generated bundle back to the branch.