2022-10-03 04:30:21 -06:00
|
|
|
name: Write changelog for dependabot PR
|
|
|
|
on:
|
|
|
|
pull_request:
|
|
|
|
types:
|
|
|
|
- opened
|
2022-10-03 10:16:45 -06:00
|
|
|
- reopened # For debugging!
|
2022-10-03 04:30:21 -06:00
|
|
|
|
2022-10-03 07:34:50 -06:00
|
|
|
permissions:
|
2023-01-04 09:46:25 -07:00
|
|
|
# Needed to be able to push the commit. See
|
2022-10-03 07:34:50 -06:00
|
|
|
# https://docs.github.com/en/code-security/dependabot/working-with-dependabot/automating-dependabot-with-github-actions#enable-auto-merge-on-a-pull-request
|
|
|
|
# for a similar example
|
|
|
|
contents: write
|
|
|
|
|
2022-10-03 04:30:21 -06:00
|
|
|
jobs:
|
|
|
|
add-changelog:
|
|
|
|
runs-on: 'ubuntu-latest'
|
|
|
|
if: ${{ github.actor == 'dependabot[bot]' }}
|
|
|
|
steps:
|
|
|
|
- uses: actions/checkout@v3
|
|
|
|
with:
|
|
|
|
ref: ${{ github.event.pull_request.head.ref }}
|
|
|
|
- name: Write, commit and push changelog
|
2023-01-04 09:46:25 -07:00
|
|
|
env:
|
|
|
|
PR_TITLE: ${{ github.event.pull_request.title }}
|
|
|
|
PR_NUMBER: ${{ github.event.pull_request.number }}
|
2022-10-03 04:30:21 -06:00
|
|
|
run: |
|
2023-01-04 09:46:25 -07:00
|
|
|
echo "${PR_TITLE}." > "changelog.d/${PR_NUMBER}".misc
|
2022-10-03 04:30:21 -06:00
|
|
|
git add changelog.d
|
|
|
|
git config user.email "github-actions[bot]@users.noreply.github.com"
|
|
|
|
git config user.name "GitHub Actions"
|
|
|
|
git commit -m "Changelog"
|
|
|
|
git push
|
|
|
|
shell: bash
|
2022-10-03 12:29:53 -06:00
|
|
|
# The `git push` above does not trigger CI on the dependabot PR.
|
2022-10-03 10:16:45 -06:00
|
|
|
#
|
|
|
|
# By default, workflows can't trigger other workflows when they're just using the
|
|
|
|
# default `GITHUB_TOKEN` access token. (This is intended to stop you from writing
|
|
|
|
# recursive workflow loops by accident, because that'll get very expensive very
|
|
|
|
# quickly.) Instead, you have to manually call out to another workflow, or else
|
|
|
|
# make your changes (i.e. the `git push` above) using a personal access token.
|
|
|
|
# See
|
|
|
|
# https://docs.github.com/en/actions/using-workflows/triggering-a-workflow#triggering-a-workflow-from-a-workflow
|
2022-10-03 12:29:53 -06:00
|
|
|
#
|
|
|
|
# I have tried and failed to find a way to trigger CI on the "merge ref" of the PR.
|
|
|
|
# See git commit history for previous attempts. If anyone desperately wants to try
|
|
|
|
# again in the future, make a matrix-bot account and use its access token to git push.
|
2022-10-03 10:16:45 -06:00
|
|
|
|
2022-10-03 12:29:53 -06:00
|
|
|
# THIS WORKFLOW HAS WRITE PERMISSIONS---do not add other jobs here unless they
|
2022-10-03 08:59:32 -06:00
|
|
|
# are sufficiently locked down to dependabot only as above.
|