Build using CI and restrict commits by users (#924)

This commit is contained in:
Robin Raju authored and GitHub committed 2026-04-07 00:04:53 +01:00
1 parent 1f7f974dea
commit a932998710
5 files changed
+100 -65

No files matched your search

+61 -46
View File
@@ -1,75 +1,90 @@
# In TypeScript actions, `dist/` is a special directory. When you reference name: Update dist
# an action with the `uses:` property, `dist/index.js` is the code that will be
# run. For this project, the `dist/index.js` file is transpiled from other
# source files. This workflow ensures the `dist/` directory contains the
# expected transpiled code.
#
# If this workflow is run from a feature branch, it will act as an additional CI
# check and fail if the checked-in `dist/` directory does not match what is
# expected from the build.
name: Check Transpiled JavaScript
on: on:
pull_request: workflow_run:
branches: workflows:
- main - Build and Test
push: types:
- completed
branches: branches:
- main - main
permissions: permissions:
contents: read contents: read
concurrency:
group: update-dist-main
cancel-in-progress: false
jobs: jobs:
check-dist: publish-dist:
name: Check dist/ if: >-
${{
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push'
}}
name: Publish dist
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions:
contents: write
steps: steps:
- name: Checkout - name: Checkout main
id: checkout
uses: actions/checkout@v6 uses: actions/checkout@v6
with:
ref: main
fetch-depth: 0
- name: Ensure main is still at the validated commit
id: tip-check
shell: bash
run: |
current_head="$(git rev-parse HEAD)"
validated_head="${{ github.event.workflow_run.head_sha }}"
if [ "$current_head" = "$validated_head" ]; then
echo "publish=true" >> "$GITHUB_OUTPUT"
exit 0
fi
echo "publish=false" >> "$GITHUB_OUTPUT"
echo "main moved from $validated_head to $current_head; a newer successful Build and Test run will refresh dist."
- name: Setup Node.js - name: Setup Node.js
id: setup-node if: steps.tip-check.outputs.publish == 'true'
uses: actions/setup-node@v6 uses: actions/setup-node@v6
with: with:
node-version-file: '.node-version' node-version-file: '.node-version'
cache: npm cache: npm
- name: Install Dependencies - name: Install dependencies
id: install if: steps.tip-check.outputs.publish == 'true'
run: npm ci run: npm ci
- name: Build dist/ Directory - name: Build dist
id: build if: steps.tip-check.outputs.publish == 'true'
run: npm run package run: npm run package
# This will fail the workflow if the `dist/` directory is different than - name: Detect dist changes
# expected. if: steps.tip-check.outputs.publish == 'true'
- name: Compare Directories id: dist-status
id: diff shell: bash
run: | run: |
if [ ! -d dist/ ]; then if ! git diff --quiet -- dist/ || \
echo "Expected dist/ directory does not exist. See status below:"
ls -la ./
exit 1
fi
if ! git diff --ignore-space-at-eol --text --quiet -- dist/ || \
[ -n "$(git ls-files --others --exclude-standard -- dist/)" ]; then [ -n "$(git ls-files --others --exclude-standard -- dist/)" ]; then
echo "Detected uncommitted changes after build. See status below:" echo "changed=true" >> "$GITHUB_OUTPUT"
git --no-pager status --short -- dist/ git --no-pager status --short -- dist/
git --no-pager diff --ignore-space-at-eol --text -- dist/ exit 0
exit 1
fi fi
# If `dist/` was different than expected, upload the expected version as a echo "changed=false" >> "$GITHUB_OUTPUT"
# workflow artifact.
- if: ${{ failure() && steps.diff.outcome == 'failure' }} - name: Commit refreshed dist
name: Upload Artifact if: steps.dist-status.outputs.changed == 'true'
id: upload shell: bash
uses: actions/upload-artifact@v6 run: |
with: git config user.name "github-actions[bot]"
name: dist git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
path: dist/ git add dist/
git commit -m "chore: refresh dist [skip ci]"
git push origin HEAD:main
+6
View File
@@ -16,6 +16,12 @@ env:
jobs: jobs:
build: build:
if: >-
${{
github.ref != 'refs/heads/main' ||
github.actor != 'github-actions[bot]' ||
!contains(github.event.head_commit.message, '[skip ci]')
}}
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
+14
View File
@@ -20,6 +20,20 @@ jobs:
steps: steps:
- name: Checkout Repo - name: Checkout Repo
uses: actions/checkout@v6 uses: actions/checkout@v6
with:
fetch-depth: 0
- name: Reject committed dist changes
shell: bash
run: |
dist_changes="$(git diff --name-only "${{ github.event.pull_request.base.sha }}"..HEAD -- dist)"
if [ -n "$dist_changes" ]; then
echo "dist/ is CI-managed and must not be changed in pull requests."
echo "Changed dist files:"
echo "$dist_changes"
exit 1
fi
- name: Setup node and cache dependencies - name: Setup node and cache dependencies
uses: actions/setup-node@v6 uses: actions/setup-node@v6
+13 -19
View File
@@ -11,14 +11,19 @@ Install dependencies
npm install npm install
``` ```
Build the distributable bundle and refresh the checked-in `dist/` output Build the distributable bundle locally when you need to exercise the action from
this checkout
```bash ```bash
npm run package npm run package
``` ```
If you change runtime code under `src/`, run `npm run package` and commit the `dist/` is CI-managed. Pull requests must not include `dist/` changes; PR
updated `dist/` contents. CI verifies that the committed bundle stays in sync. validation rejects them, and a post-merge workflow rebuilds and commits the
generated bundle back to `main`.
If you only needed a local bundle for debugging, discard the generated `dist/`
changes before committing.
Run tests :heavy_check_mark: Run tests :heavy_check_mark:
@@ -72,23 +77,12 @@ See the
[toolkit documentation](https://github.com/actions/toolkit/blob/master/README.md#packages) [toolkit documentation](https://github.com/actions/toolkit/blob/master/README.md#packages)
for the various packages. for the various packages.
## Publish to a distribution branch ## Dist publication
Actions are run from GitHub repos so we will checkin the packed dist folder. This repository keeps `dist/` in Git because `action.yml` points to
`dist/index.js`, but contributors do not publish it manually. After a change
Then run [ncc](https://github.com/zeit/ncc) and push the results: lands on `main`, GitHub Actions rebuilds `dist/` and commits the generated
bundle back to the branch with the Actions bot.
```bash
$ npm run package
$ git add dist
$ git commit -a -m "prod dependencies"
$ git push origin releases/v1
```
Your action is now published! :rocket:
See the
[versioning documentation](https://github.com/actions/toolkit/blob/master/docs/action-versioning.md)
## Validate ## Validate
+6
View File
@@ -184,3 +184,9 @@ ${{steps.<step-id>.outputs.tag_name}}
latest: true latest: true
preRelease: true preRelease: true
``` ```
## Development notes
`dist/` is CI-managed for this repository. Pull requests should include source,
tests, and workflow changes only; after a merge to `main`, GitHub Actions
rebuilds `dist/` and commits the generated bundle back to the branch.