From 77ffeb4514ccea695287de33a635ee91e730576d Mon Sep 17 00:00:00 2001 From: Thore Cimbal Date: Thu, 30 Jul 2026 12:00:00 +0000 Subject: [PATCH] ci: reduce workflows to fork-relevant CI, fix upstream checkouts (Issue #2) Removed ~37 workflow files that are unmodified upstream tooling this fork doesn't use (Netlify, SonarCloud, Localazy, release-drafter/backport, GitHub issue-triage bots, npm-publish, Cloudflare Pages deploy, Docker push to ghcr.io/element-hq). Enabling Actions for this repo would have activated all of them simultaneously against a single-capacity shared runner - most would just fail loudly and starve the one job slot shared with other repos. Kept build-and-test.yaml (the actual comprehensive build+test+desktop workflow) and its build_desktop_*.yaml sub-workflows. Fixed: push trigger now targets `main` (was `staging`/`master`, neither of which exist here - push events never fired at all before), 4 checkout steps now check out this fork instead of element-hq/element-web, and removed the macOS desktop build job since the registered runner (builder-1) has no macOS label and would queue forever instead of failing cleanly. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/backport.yml | 34 -- .github/workflows/build-and-test-netlify.yaml | 48 --- .github/workflows/build-and-test.yaml | 21 +- .github/workflows/build.yml | 76 ----- .github/workflows/build_debian.yaml | 86 ----- .../workflows/build_desktop_and_deploy.yaml | 313 ------------------ .github/workflows/build_desktop_prepare.yaml | 2 +- .github/workflows/build_develop.yml | 141 -------- .github/workflows/cd.yaml | 75 ----- .github/workflows/deploy.yml | 101 ------ .github/workflows/docker.yaml | 181 ---------- .github/workflows/docs.yml | 55 --- .github/workflows/issue_closed.yml | 157 --------- .github/workflows/localazy_download.yaml | 14 - .github/workflows/localazy_upload.yaml | 14 - .github/workflows/merge-queue.yaml | 29 -- .github/workflows/netlify.yaml | 53 --- .github/workflows/npm-publish.yaml | 47 --- .github/workflows/pull_request.yaml | 16 - .../workflows/pull_request_base_branch.yaml | 17 - .github/workflows/release-drafter.yml | 12 - .github/workflows/release-gitflow.yml | 17 - .github/workflows/release.yml | 68 ---- .github/workflows/release_prepare.yml | 97 ------ .../shared-component-storybook-build.yml | 38 --- .../shared-component-storybook-publish.yaml | 33 -- ...shared-component-visual-tests-netlify.yaml | 50 --- .../shared-component-visual-tests.yaml | 60 ---- .github/workflows/sonarqube.yml | 27 -- .github/workflows/static_analysis.yaml | 133 -------- .github/workflows/sync-labels.yml | 24 -- .github/workflows/tests.yml | 188 ----------- .github/workflows/triage-assigned.yml | 21 -- .github/workflows/triage-incoming.yml | 16 - .github/workflows/triage-labelled.yml | 178 ---------- .../workflows/triage-move-review-requests.yml | 140 -------- .github/workflows/triage-stale.yml | 29 -- .github/workflows/triage-unlabelled.yml | 54 --- .github/workflows/update-jitsi.yml | 37 --- .github/workflows/update-topics.yaml | 119 ------- 40 files changed, 7 insertions(+), 2814 deletions(-) delete mode 100644 .github/workflows/backport.yml delete mode 100644 .github/workflows/build-and-test-netlify.yaml delete mode 100644 .github/workflows/build.yml delete mode 100644 .github/workflows/build_debian.yaml delete mode 100644 .github/workflows/build_desktop_and_deploy.yaml delete mode 100644 .github/workflows/build_develop.yml delete mode 100644 .github/workflows/cd.yaml delete mode 100644 .github/workflows/deploy.yml delete mode 100644 .github/workflows/docker.yaml delete mode 100644 .github/workflows/docs.yml delete mode 100644 .github/workflows/issue_closed.yml delete mode 100644 .github/workflows/localazy_download.yaml delete mode 100644 .github/workflows/localazy_upload.yaml delete mode 100644 .github/workflows/merge-queue.yaml delete mode 100644 .github/workflows/netlify.yaml delete mode 100644 .github/workflows/npm-publish.yaml delete mode 100644 .github/workflows/pull_request.yaml delete mode 100644 .github/workflows/pull_request_base_branch.yaml delete mode 100644 .github/workflows/release-drafter.yml delete mode 100644 .github/workflows/release-gitflow.yml delete mode 100644 .github/workflows/release.yml delete mode 100644 .github/workflows/release_prepare.yml delete mode 100644 .github/workflows/shared-component-storybook-build.yml delete mode 100644 .github/workflows/shared-component-storybook-publish.yaml delete mode 100644 .github/workflows/shared-component-visual-tests-netlify.yaml delete mode 100644 .github/workflows/shared-component-visual-tests.yaml delete mode 100644 .github/workflows/sonarqube.yml delete mode 100644 .github/workflows/static_analysis.yaml delete mode 100644 .github/workflows/sync-labels.yml delete mode 100644 .github/workflows/tests.yml delete mode 100644 .github/workflows/triage-assigned.yml delete mode 100644 .github/workflows/triage-incoming.yml delete mode 100644 .github/workflows/triage-labelled.yml delete mode 100644 .github/workflows/triage-move-review-requests.yml delete mode 100644 .github/workflows/triage-stale.yml delete mode 100644 .github/workflows/triage-unlabelled.yml delete mode 100644 .github/workflows/update-jitsi.yml delete mode 100644 .github/workflows/update-topics.yaml diff --git a/.github/workflows/backport.yml b/.github/workflows/backport.yml deleted file mode 100644 index c770fb248..000000000 --- a/.github/workflows/backport.yml +++ /dev/null @@ -1,34 +0,0 @@ -name: Backport -on: - # Privilege escalation necessary to enable backporting PRs from forks - # 🚨 We must not execute any checked out code here. - pull_request_target: # zizmor: ignore[dangerous-triggers] - types: - - closed - - labeled - branches: - - develop - -permissions: {} # We use ELEMENT_BOT_TOKEN instead - -jobs: - backport: - name: Backport - runs-on: ubuntu-24.04 - # Only react to merged PRs for security reasons. - # See https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target. - if: > - github.event.pull_request.merged - && ( - github.event.action == 'closed' - || ( - github.event.action == 'labeled' - && contains(github.event.label.name, 'backport') - ) - ) - steps: - - uses: tibdex/backport@9565281eda0731b1d20c4025c43339fb0a23812e # v2 - with: - labels_template: "<%= JSON.stringify([...labels, 'X-Release-Blocker']) %>" - # We can't use GITHUB_TOKEN here or CI won't run on the new PR - github_token: ${{ secrets.ELEMENT_BOT_TOKEN }} diff --git a/.github/workflows/build-and-test-netlify.yaml b/.github/workflows/build-and-test-netlify.yaml deleted file mode 100644 index 1b3aa2bd6..000000000 --- a/.github/workflows/build-and-test-netlify.yaml +++ /dev/null @@ -1,48 +0,0 @@ -# Triggers after the playwright tests have finished, -# taking the artifact and uploading it to Netlify for easier viewing -name: Upload End to End Test report to Netlify -on: - # Privilege escalation necessary to publish to Netlify - # 🚨 We must not execute any checked out code here. - workflow_run: # zizmor: ignore[dangerous-triggers] - workflows: ["Build & Test"] - types: - - completed - -concurrency: - group: ${{ github.workflow }}-${{ github.event.workflow_run.head_branch || github.run_id }} - cancel-in-progress: ${{ github.event.workflow_run.event == 'pull_request' }} - -permissions: {} - -jobs: - report: - if: github.event.workflow_run.conclusion != 'cancelled' - name: Report results - runs-on: ubuntu-24.04 - environment: Netlify - permissions: - statuses: write - deployments: write - actions: read - steps: - - name: Download HTML report - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - run-id: ${{ github.event.workflow_run.id }} - name: html-report - path: playwright-report - - - name: 📤 Deploy to Netlify - uses: matrix-org/netlify-pr-preview@9805cd123fc9a7e421e35340a05e1ebc5dee46b5 # v3 - with: - path: playwright-report - owner: ${{ github.event.workflow_run.head_repository.owner.login }} - branch: ${{ github.event.workflow_run.head_branch }} - revision: ${{ github.event.workflow_run.head_sha }} - token: ${{ secrets.NETLIFY_AUTH_TOKEN }} - site_id: ${{ vars.NETLIFY_SITE_ID }} - desc: Playwright Report - deployment_env: EndToEndTests - prefix: "e2e-" diff --git a/.github/workflows/build-and-test.yaml b/.github/workflows/build-and-test.yaml index c1ecb609f..93cddf408 100644 --- a/.github/workflows/build-and-test.yaml +++ b/.github/workflows/build-and-test.yaml @@ -16,8 +16,7 @@ on: merge_group: types: [checks_requested] push: - # We do not build on push to develop as the merge_group check handles that - branches: [staging, master] + branches: [main] # support triggering from other workflows workflow_call: @@ -60,7 +59,7 @@ jobs: - name: Checkout code uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: - repository: element-hq/element-web + repository: ${{ github.repository }} persist-credentials: false - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 @@ -137,7 +136,7 @@ jobs: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: persist-credentials: false - repository: element-hq/element-web + repository: ${{ github.repository }} - name: 📥 Download artifact uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 @@ -237,15 +236,8 @@ jobs: arch: ${{ matrix.arch }} blob_report: true - build_ed_macos: - needs: prepare_ed - name: "Desktop macOS" - uses: ./.github/workflows/build_desktop_macos.yaml - # Skip macOS builds on PRs, as the Linux amd64 build is enough of a smoke test and includes the screenshot tests - # and we have a very low limit of concurrent macos runners (5) across the Github org. - if: github.event_name != 'pull_request' || contains(github.event.pull_request.labels.*.name, 'X-Run-All-Tests') - with: - blob_report: true + # build_ed_macos entfernt: der einzige Gitea-Actions-Runner (builder-1, CFGMON) hat + # kein macOS-Label - der Job wuerde nie einen Runner finden statt sauber zu scheitern. complete: name: end-to-end-tests @@ -256,7 +248,6 @@ jobs: - prepare_ed - build_ed_windows - build_ed_linux - - build_ed_macos if: always() runs-on: ubuntu-24.04 steps: @@ -264,7 +255,7 @@ jobs: if: needs.build_ew.outputs.skip == 'false' with: persist-credentials: false - repository: element-hq/element-web + repository: ${{ github.repository }} - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 if: needs.build_ew.outputs.skip == 'false' diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml deleted file mode 100644 index 5f93a9451..000000000 --- a/.github/workflows/build.yml +++ /dev/null @@ -1,76 +0,0 @@ -name: Build -on: - pull_request: {} - push: - branches: [develop, master] - merge_group: - types: [checks_requested] -concurrency: - group: ${{ github.workflow }}-${{ github.head_ref || github.sha }} - cancel-in-progress: ${{ github.event_name == 'pull_request' }} -# develop pushes and repository_dispatch handled in build_develop.yaml -env: - # This must be set for fetchdep.sh to get the right branch - PR_NUMBER: ${{ github.event.pull_request.number }} - NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes -permissions: {} # No permissions required -jobs: - build: - name: "Build on ${{ matrix.image }}" - # We build on all 3 platforms to ensure we don't have any OS-specific build incompatibilities - strategy: - fail-fast: false - matrix: - image: - - ubuntu-24.04 - - windows-2022 - - macos-14 - isDevelop: - - ${{ github.event_name == 'push' && github.ref_name == 'develop' }} - isPullRequest: - - ${{ github.event_name == 'pull_request' }} - # Skip the ubuntu-24.04 build for the develop branch as the dedicated CD build_develop workflow handles that - # Skip the non-linux builds for pull requests as Windows is awfully slow, so run in merge queue only - exclude: - - isDevelop: true - image: ubuntu-24.04 - - isPullRequest: true - image: windows-2022 - - isPullRequest: true - image: macos-14 - runs-on: ${{ matrix.image }} - defaults: - run: - shell: bash - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - # Disable cache on Windows as it is slower than not caching - # https://github.com/actions/setup-node/issues/975 - cache: ${{ runner.os != 'Windows' && 'pnpm' || '' }} - node-version: "lts/*" - - - name: Fetch layered build - run: ./scripts/layered.sh - - - name: Copy config - working-directory: apps/web - run: cp element.io/develop/config.json config.json - - - name: Build - working-directory: apps/web - env: - CI_PACKAGE: true - run: VERSION=$(scripts/get-version-from-git.sh) pnpm run build - - - name: Upload Artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: webapp-${{ matrix.image }} - path: apps/web/webapp - retention-days: 1 diff --git a/.github/workflows/build_debian.yaml b/.github/workflows/build_debian.yaml deleted file mode 100644 index 24fe492e7..000000000 --- a/.github/workflows/build_debian.yaml +++ /dev/null @@ -1,86 +0,0 @@ -name: Build Debian package -on: - release: - types: [published] -concurrency: ${{ github.workflow }} -permissions: {} # We use ELEMENT_BOT_TOKEN instead -jobs: - build: - name: Build package - environment: packages.element.io - runs-on: ubuntu-24.04 - env: - R2_INCOMING_BUCKET: ${{ vars.R2_INCOMING_BUCKET }} - R2_URL: ${{ vars.CF_R2_S3_API }} - VERSION: ${{ github.ref_name }} - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - name: Download package - working-directory: apps/web - run: | - wget "https://github.com/element-hq/element-web/releases/download/$VERSION/element-$VERSION.tar.gz" - wget "https://github.com/element-hq/element-web/releases/download/$VERSION/element-$VERSION.tar.gz.asc" - - - name: Check GPG signature - working-directory: apps/web - run: | - wget "https://packages.element.io/element-release-key.gpg" - gpg --import element-release-key.gpg - gpg --fingerprint "$FINGERPRINT" - gpg --verify "element-$VERSION.tar.gz.asc" "element-$VERSION.tar.gz" - env: - FINGERPRINT: ${{ vars.GPG_FINGERPRINT }} - - - name: Prepare - working-directory: apps/web - run: | - mkdir -p debian/tmp/DEBIAN - find debian -maxdepth 1 -type f -exec cp "{}" debian/tmp/DEBIAN/ \; - mkdir -p debian/tmp/usr/share/element-web/ debian/tmp/etc/element-web/ - - tar -xf "element-$VERSION.tar.gz" -C debian/tmp/usr/share/element-web --strip-components=1 --no-same-owner --no-same-permissions - mv debian/tmp/usr/share/element-web/config.sample.json debian/tmp/etc/element-web/config.json - ln -s /etc/element-web/config.json debian/tmp/usr/share/element-web/config.json - - - name: Write changelog - working-directory: apps/web - run: | - VERSION=$(cat package.json | jq -r .version) - TIME=$(date -d "$PUBLISHED_AT" -R) - { - echo "element-web ($VERSION) default; urgency=medium" - echo "$BODY" | sed 's/^##/\n */g;s/^\*/ */g' | perl -pe 's/\[.+?]\((.+?)\)/\1/g' - echo "" - echo " -- $ACTOR $TIME" - } > debian/tmp/DEBIAN/changelog - env: - ACTOR: ${{ github.actor }} - VERSION: ${{ github.event.release.tag_name }} - BODY: ${{ github.event.release.body }} - PUBLISHED_AT: ${{ github.event.release.published_at }} - - - name: Build deb package - working-directory: apps/web - run: | - VERSION=$(cat package.json | jq -r .version) - dpkg-gencontrol -v"$VERSION" -ldebian/tmp/DEBIAN/changelog - dpkg-deb -Zxz --root-owner-group --build debian/tmp element-web.deb - - - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: element-web.deb - path: apps/web/element-web.deb - retention-days: 14 - - - name: Publish to packages.element.io - if: github.event.release.prerelease == false - uses: element-hq/packages.element.io@master # zizmor: ignore[unpinned-uses] - with: - file: apps/web/element-web.deb - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - bucket-api: ${{ vars.CF_R2_S3_API }} - bucket-key-id: ${{ secrets.CF_R2_ACCESS_KEY_ID }} - bucket-access-key: ${{ secrets.CF_R2_TOKEN }} diff --git a/.github/workflows/build_desktop_and_deploy.yaml b/.github/workflows/build_desktop_and_deploy.yaml deleted file mode 100644 index 1bddf5f63..000000000 --- a/.github/workflows/build_desktop_and_deploy.yaml +++ /dev/null @@ -1,313 +0,0 @@ -name: Build and Deploy -on: - # Nightly build - schedule: - - cron: "0 9 * * *" - # Release build - release: - types: [published] - # Manual nightly & release - workflow_dispatch: - inputs: - mode: - description: What type of build to trigger. Release builds MUST be ran from the `master` branch. - required: true - default: nightly - type: choice - options: - - nightly - - release - macos: - description: Build macOS - required: true - type: boolean - default: true - windows: - description: Build Windows - required: true - type: boolean - default: true - linux: - description: Build Linux - required: true - type: boolean - default: true - deploy: - description: Deploy artifacts - required: true - type: boolean - default: true -run-name: Element ${{ inputs.mode != 'release' && github.event_name != 'release' && 'Nightly' || 'Desktop' }} -concurrency: ${{ github.workflow }} -env: - R2_BUCKET: ${{ vars.R2_BUCKET }} -permissions: {} # Uses ELEMENT_BOT_TOKEN -jobs: - prepare: - uses: ./.github/workflows/build_desktop_prepare.yaml - permissions: - contents: read - with: - config: element.io/${{ inputs.mode || (github.event_name == 'release' && 'release') || 'nightly' }} - version: ${{ (inputs.mode != 'release' && github.event_name != 'release') && 'develop' || '' }} - nightly: ${{ inputs.mode != 'release' && github.event_name != 'release' }} - deploy: ${{ inputs.deploy || (github.event_name != 'workflow_dispatch' && github.event.release.prerelease != true) }} - secrets: - CF_R2_ACCESS_KEY_ID: ${{ secrets.CF_R2_ACCESS_KEY_ID }} - CF_R2_TOKEN: ${{ secrets.CF_R2_TOKEN }} - - trigger-pro-pipeline: - name: Trigger Pro pipeline - needs: prepare - runs-on: ubuntu-24.04 - steps: - - uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4 - with: - repository: element-hq/element-web-pro - token: ${{ secrets.ELEMENT_BOT_TOKEN }} - event-type: trigger-pipeline - client-payload: |- - { - "base-ref": "${{ github.ref_name }}" - } - - windows: - if: github.event_name != 'workflow_dispatch' || inputs.windows - needs: prepare - name: Windows ${{ matrix.arch }} - strategy: - matrix: - arch: [x64, arm64] - uses: ./.github/workflows/build_desktop_windows.yaml - secrets: inherit # zizmor: ignore[secrets-inherit] - with: - sign: true - arch: ${{ matrix.arch }} - version: ${{ needs.prepare.outputs.nightly-version }} - - macos: - if: github.event_name != 'workflow_dispatch' || inputs.macos - needs: prepare - name: macOS - uses: ./.github/workflows/build_desktop_macos.yaml - secrets: inherit # zizmor: ignore[secrets-inherit] - with: - sign: true - base-url: https://packages.element.io/${{ needs.prepare.outputs.packages-dir }} - version: ${{ needs.prepare.outputs.nightly-version }} - - linux: - if: github.event_name != 'workflow_dispatch' || inputs.linux - needs: prepare - name: Linux ${{ matrix.arch }} (sqlcipher ${{ matrix.sqlcipher }}) - strategy: - matrix: - arch: [amd64, arm64] - sqlcipher: [static] - uses: ./.github/workflows/build_desktop_linux.yaml - with: - arch: ${{ matrix.arch }} - sqlcipher: ${{ matrix.sqlcipher }} - version: ${{ needs.prepare.outputs.nightly-version }} - - deploy: - needs: - - prepare - - macos - - linux - - windows - runs-on: ubuntu-24.04 - name: ${{ needs.prepare.outputs.deploy == 'true' && 'Deploy' || 'Deploy (dry-run)' }} - if: always() && !contains(needs.*.result, 'failure') && !contains(needs.*.result, 'cancelled') - environment: ${{ needs.prepare.outputs.deploy == 'true' && 'packages.element.io' || '' }} - steps: - - name: Download artifacts - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - - - name: Prepare artifacts for deployment - run: | - set -ex - - # Windows - for arch in x64 arm64 - do - if [ -d "win-$arch" ]; then - mkdir -p packages.element.io/{install,update}/win32/$arch - mv win-$arch/squirrel-windows*/*.exe "packages.element.io/install/win32/$arch/" - mv win-$arch/squirrel-windows*/*.nupkg "packages.element.io/update/win32/$arch/" - mv win-$arch/squirrel-windows*/RELEASES "packages.element.io/update/win32/$arch/" - fi - done - - # macOS - if [ -d macos ]; then - mkdir -p packages.element.io/{install,update}/macos - mv macos/*.dmg packages.element.io/install/macos/ - mv macos/*-mac.zip packages.element.io/update/macos/ - mv macos/*.json packages.element.io/update/macos/ - fi - - # Linux - if [ -d linux-amd64-sqlcipher-static ]; then - mkdir -p packages.element.io/install/linux/glibc-x86-64 - mv linux-amd64-sqlcipher-static/*.tar.gz packages.element.io/install/linux/glibc-x86-64 - fi - if [ -d linux-arm64-sqlcipher-static ]; then - mkdir -p packages.element.io/install/linux/glibc-aarch64 - mv linux-arm64-sqlcipher-static/*.tar.gz packages.element.io/install/linux/glibc-aarch64 - fi - - # We don't wish to store the installer for every nightly ever, so we only keep the latest - - name: "[Nightly] Strip version from installer file" - if: needs.prepare.outputs.nightly-version != '' - run: | - set -ex - - # Windows - for arch in x64 arm64 - do - if [ -d "win-$arch" ]; then mv packages.element.io/install/win32/$arch/{*,"Element Nightly Setup"}.exe; fi - done - - # macOS - if [ -d macos ]; then mv packages.element.io/install/macos/{*,"Element Nightly"}.dmg; fi - - # Linux - if [ -d linux-amd64-sqlcipher-static ]; then mv packages.element.io/install/linux/glibc-x86-64/{*,element-desktop-nightly}.tar.gz; fi - if [ -d linux-arm64-sqlcipher-static ]; then mv packages.element.io/install/linux/glibc-aarch64/{*,element-desktop-nightly}.tar.gz; fi - - - name: "[Release] Prepare release latest symlink" - if: needs.prepare.outputs.nightly-version == '' - run: | - set -ex - - # Windows - for arch in x64 arm64 - do - if [ -d "win-$arch" ]; then - pushd packages.element.io/install/win32/$arch - ln -s "$(find . -type f -iname "*.exe" | xargs -0 -n1 -- basename)" "Element Setup.exe" - popd - fi - done - - # macOS - if [ -d macos ]; then - pushd packages.element.io/install/macos - ln -s "$(find . -type f -iname "*.dmg" | xargs -0 -n1 -- basename)" "Element.dmg" - popd - fi - - # Linux - if [ -d linux-amd64-sqlcipher-static ]; then - pushd packages.element.io/install/linux/glibc-x86-64 - ln -s "$(find . -type f -iname "*.tar.gz" | xargs -0 -n1 -- basename)" "element-desktop.tar.gz" - popd - fi - if [ -d linux-arm64-sqlcipher-static ]; then - pushd packages.element.io/install/linux/glibc-aarch64 - ln -s "$(find . -type f -iname "*.tar.gz" | xargs -0 -n1 -- basename)" "element-desktop.tar.gz" - popd - fi - - - name: Stash packages.element.io - if: needs.prepare.outputs.deploy == 'false' - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: packages.element.io - path: packages.element.io - - # Checksum algorithm specified as per https://developers.cloudflare.com/r2/examples/aws/aws-cli/ - - name: Deploy artifacts - if: needs.prepare.outputs.deploy == 'true' - run: | - set -x - aws s3 cp --recursive packages.element.io/ s3://$R2_BUCKET/$DEPLOYMENT_DIR --endpoint-url $R2_URL --region auto --checksum-algorithm CRC32 - env: - AWS_ACCESS_KEY_ID: ${{ secrets.CF_R2_ACCESS_KEY_ID }} - AWS_SECRET_ACCESS_KEY: ${{ secrets.CF_R2_TOKEN }} - R2_URL: ${{ vars.CF_R2_S3_API }} - DEPLOYMENT_DIR: ${{ needs.prepare.outputs.packages-dir }} - - - name: Notify packages.element.io of new files - if: needs.prepare.outputs.deploy == 'true' - uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4 - with: - token: ${{ secrets.ELEMENT_BOT_TOKEN }} - repository: element-hq/packages.element.io - event-type: packages-index - - - name: Find debs - id: deb - if: needs.linux.result == 'success' - run: | - set -x - - for arch in amd64 arm64 - do - echo "$arch=$(ls linux-$arch-sqlcipher-static/*.deb | tail -n1)" >> $GITHUB_OUTPUT - done - - - name: Stash debs - if: needs.prepare.outputs.deploy == 'false' && needs.linux.result == 'success' - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: debs - path: | - ${{ steps.deb.outputs.amd64 }} - ${{ steps.deb.outputs.arm64 }} - - - name: Publish amd64 deb to packages.element.io - uses: element-hq/packages.element.io@master # zizmor: ignore[unpinned-uses] - if: needs.prepare.outputs.deploy == 'true' && needs.linux.result == 'success' - with: - file: ${{ steps.deb.outputs.amd64 }} - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - bucket-api: ${{ vars.CF_R2_S3_API }} - bucket-key-id: ${{ secrets.CF_R2_ACCESS_KEY_ID }} - bucket-access-key: ${{ secrets.CF_R2_TOKEN }} - - - name: Publish arm64 deb to packages.element.io - uses: element-hq/packages.element.io@master # zizmor: ignore[unpinned-uses] - if: needs.prepare.outputs.deploy == 'true' && needs.linux.result == 'success' - with: - file: ${{ steps.deb.outputs.arm64 }} - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - bucket-api: ${{ vars.CF_R2_S3_API }} - bucket-key-id: ${{ secrets.CF_R2_ACCESS_KEY_ID }} - bucket-access-key: ${{ secrets.CF_R2_TOKEN }} - - deploy-ess: - needs: deploy - runs-on: ubuntu-24.04 - name: Deploy builds to ESS - if: needs.prepare.outputs.deploy == 'true' && github.event_name == 'release' - env: - BUCKET_NAME: "element-desktop-msi.onprem.element.io" - AWS_REGION: "eu-central-1" - permissions: - id-token: write # This is required for requesting the JWT - steps: - - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@d979d5b3a71173a29b74b5b88418bfda9437d885 # v6 - with: - role-to-assume: arn:aws:iam::264135176173:role/Push-ElementDesktop-MSI - role-session-name: githubaction-run-${{ github.run_id }} - aws-region: ${{ env.AWS_REGION }} - - - name: Download artifacts - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - pattern: win-* - - - name: Copy files to S3 - run: | - set -x - - PREFIX="${VERSION%.*}" - for file in win-*/*.msi; do - filename=$(basename "$file") - aws s3 cp "$file" "s3://${{ env.BUCKET_NAME }}/$PREFIX/$filename" - done - env: - VERSION: ${{ github.event.release.tag_name }} diff --git a/.github/workflows/build_desktop_prepare.yaml b/.github/workflows/build_desktop_prepare.yaml index 2420e907c..f5c7ee24b 100644 --- a/.github/workflows/build_desktop_prepare.yaml +++ b/.github/workflows/build_desktop_prepare.yaml @@ -56,7 +56,7 @@ jobs: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: persist-credentials: false - repository: element-hq/element-web + repository: ${{ github.repository }} - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 diff --git a/.github/workflows/build_develop.yml b/.github/workflows/build_develop.yml deleted file mode 100644 index 246363b1d..000000000 --- a/.github/workflows/build_develop.yml +++ /dev/null @@ -1,141 +0,0 @@ -# Separate to the main build workflow for access to develop -# environment secrets, largely similar to build.yaml. -name: Build and Deploy develop -on: - push: - branches: [develop] - repository_dispatch: - types: [element-web-notify] -concurrency: - group: ${{ github.repository_owner }}-${{ github.workflow }}-${{ github.ref_name }} - cancel-in-progress: true -env: - NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes -permissions: {} -jobs: - build: - name: "Build & Deploy develop.element.io" - # Only respect triggers from our develop branch, ignore that of forks - if: github.repository == 'element-hq/element-web' - runs-on: ubuntu-24.04 - environment: develop - permissions: - checks: read - pages: write - deployments: write - env: - R2_BUCKET: "element-web-develop" - R2_URL: ${{ vars.CF_R2_S3_API }} - R2_PUBLIC_URL: "https://element-web-develop.element.io" - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - cache: "pnpm" - node-version: "lts/*" - - - name: Install Dependencies - run: "./scripts/layered.sh" - - - name: Build, Package & Upload sourcemaps - working-directory: apps/web - run: "./scripts/ci_package.sh" - env: - SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} - SENTRY_DSN: ${{ secrets.SENTRY_DSN }} - SENTRY_URL: ${{ secrets.SENTRY_URL }} - SENTRY_ORG: element - SENTRY_PROJECT: riot-web - # We only deploy the latest bundles to Cloudflare Pages and use _redirects to fallback to R2 for - # older ones. This redirect means that 'self' is insufficient in the CSP, - # and we have to add the R2 URL. - # Once Cloudflare redirects support proxying mode we will be able to ditch this. - # See Proxying in support table at https://developers.cloudflare.com/pages/platform/redirects - CSP_EXTRA_SOURCE: ${{ env.R2_PUBLIC_URL }} - - - run: mv dist/element-*.tar.gz dist/develop.tar.gz - working-directory: apps/web - - - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: webapp - path: apps/web/dist/develop.tar.gz - retention-days: 1 - - - name: Extract webapp - run: | - mkdir _deploy - tar xf apps/web/dist/develop.tar.gz -C _deploy --strip-components=1 - - - name: Copy config - run: cp apps/web/element.io/develop/config.json _deploy/config.json - - - name: Populate 404.html - run: echo "404 Not Found" > _deploy/404.html - - - name: Populate _headers - run: cp .github/cfp_headers _deploy/_headers - - # Redirect requests for the develop tarball and the historical bundles to R2 - # We find the latest 100 bundle.css files and add their bundles to the redirects file - # S3 has no sane way to get the age of a directory as they don't really exist - - name: Populate _redirects - run: | - { - echo "/develop.tar.gz $R2_PUBLIC_URL/develop.tar.gz 301" - aws s3api --region auto --endpoint-url $R2_URL list-objects-v2 --bucket $R2_BUCKET \ - --query "sort_by(Contents[?ends_with(Key, '/bundle.css')], &LastModified)[-100:].Key" \ - --prefix "bundles/" | jq -r '.[]' | grep -oE '[^\"].*\/\s*' | while read -r path ; do - echo "/${path}* $R2_PUBLIC_URL/${path}:splat 301" - done - } | tee _deploy/_redirects - env: - AWS_ACCESS_KEY_ID: ${{ secrets.CF_R2_ACCESS_KEY_ID }} - AWS_SECRET_ACCESS_KEY: ${{ secrets.CF_R2_TOKEN }} - - # We may be trying to deploy the same webapp bundles again, we need to ensure that the live bundles - # are not present in the _redirects file and instead accessed directly from Cloudflare Pages. - - name: Trim _redirects - working-directory: _deploy - run: | - find bundles -type d -mindepth 1 -maxdepth 1 -exec sed -i "\:{}:d" _redirects \; - - - name: Wait for other steps to succeed - uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork - with: - ref: ${{ github.sha }} - running-workflow-name: "Build & Deploy develop.element.io" - repo-token: ${{ secrets.GITHUB_TOKEN }} - wait-interval: 10 - check-regexp: ^((?!SonarCloud|SonarQube|issue|board|label|Release|prepare|GitHub Pages|Upload|Netlify|Report).)*$ - - # We keep the latest develop.tar.gz on R2 instead of relying on the github artifact uploaded earlier - # as the expires after 24h and requires auth to download. - # Element Desktop's fetch script uses this tarball to fetch latest develop to build Nightlies. - # Checksum algorithm specified as per https://developers.cloudflare.com/r2/examples/aws/aws-cli/ - - name: Deploy to R2 - run: | - aws s3 cp apps/web/dist/develop.tar.gz s3://$R2_BUCKET/develop.tar.gz --endpoint-url $R2_URL --region=auto --checksum-algorithm CRC32 - aws s3 cp _deploy/ s3://$R2_BUCKET/ --recursive --endpoint-url $R2_URL --region=auto --checksum-algorithm CRC32 - env: - AWS_ACCESS_KEY_ID: ${{ secrets.CF_R2_ACCESS_KEY_ID }} - AWS_SECRET_ACCESS_KEY: ${{ secrets.CF_R2_TOKEN }} - - - name: Deploy to Cloudflare Pages - id: cfp - uses: cloudflare/pages-action@f0a1cd58cd66095dee69bfa18fa5efd1dde93bca # v1 - with: - apiToken: ${{ secrets.CF_PAGES_TOKEN }} - accountId: ${{ secrets.CF_PAGES_ACCOUNT_ID }} - projectName: element-web-develop - directory: _deploy - gitHubToken: ${{ secrets.GITHUB_TOKEN }} - - - run: | - echo "Deployed to ${STEPS_CFP_OUTPUTS_URL}" >> $GITHUB_STEP_SUMMARY - env: - STEPS_CFP_OUTPUTS_URL: ${{ steps.cfp.outputs.url }} diff --git a/.github/workflows/cd.yaml b/.github/workflows/cd.yaml deleted file mode 100644 index d03f08487..000000000 --- a/.github/workflows/cd.yaml +++ /dev/null @@ -1,75 +0,0 @@ -name: CD # Continuous Delivery -on: - push: - branches: [master, staging, develop] - paths: - - "**/Dockerfile" - - "**/dockerbuild" - - "**/docker" - - "**/docker-*" - - "pnpm-lock.yaml" - -concurrency: ${{ github.workflow }}-${{ github.ref_name }} - -permissions: {} -env: - NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes - -jobs: - docker: - name: Docker Bake - runs-on: ubuntu-24.04 - permissions: - id-token: write # needed for signing the images with GitHub OIDC Token - packages: write # needed for publishing packages to GHCR - # Needed for nx-set-shas - contents: read - actions: read - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - name: Install Cosign - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - - - name: Set up QEMU - uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4 - - - name: Set up Docker Buildx - id: builder - uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4 - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - node-version-file: package.json - cache: "pnpm" - - - name: Install Deps - run: "pnpm install --frozen-lockfile" - - - name: Login to GitHub Container Registry - uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4 - with: - registry: ghcr.io - username: ${{ github.repository_owner }} - password: ${{ secrets.GITHUB_TOKEN }} - - - run: pnpm nx run-many --nxBail -t docker:build - id: build - env: - INPUT_PUSH: true - INPUT_LOAD: false - INPUT_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - INPUT_BUILDER: ${{ steps.builder.outputs.name }} - - - name: Sign the images with GitHub OIDC token - run: | - shopt -s globstar - - for FILE in ./node_modules/.cache/nx-container/**/metadata; do - TARGET=$(jq -r '(.["image.name"] | split(",") | last) + "@" + .["containerimage.digest"]' "$FILE") - echo "Signing $TARGET..." - cosign sign --yes "$TARGET" - done diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml deleted file mode 100644 index 238b88128..000000000 --- a/.github/workflows/deploy.yml +++ /dev/null @@ -1,101 +0,0 @@ -# Manual deploy workflow for deploying to app.element.io & staging.element.io -# Runs automatically for staging.element.io when an RC or Release is published -# Note: Does *NOT* run automatically for app.element.io so that it gets tested on staging.element.io beforehand -name: Deploy release -run-name: Deploy ${{ github.ref_name }} to ${{ inputs.site || 'staging.element.io' }} -on: - release: - types: [published] - workflow_dispatch: - inputs: - site: - description: Which site to deploy to - required: true - default: staging.element.io - type: choice - options: - - staging.element.io - - app.element.io - skip-checks: - description: Skip CI on the tagged commit - required: true - default: false - type: boolean -concurrency: ${{ inputs.site || 'staging.element.io' }} -permissions: {} -jobs: - deploy: - name: "Deploy to Cloudflare Pages" - runs-on: ubuntu-24.04 - environment: ${{ inputs.site || 'staging.element.io' }} - permissions: - checks: read - deployments: write - env: - SITE: ${{ inputs.site || 'staging.element.io' }} - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - name: Load GPG key - run: | - curl https://packages.element.io/element-release-key.gpg | gpg --import - gpg -k "$GPG_FINGERPRINT" - env: - GPG_FINGERPRINT: ${{ vars.GPG_FINGERPRINT }} - - - name: Check current version on deployment - id: current_version - run: | - version=$(curl -s https://$SITE/version) - echo "version=${version#v}" >> $GITHUB_OUTPUT - - # The current version bundle melding dance is skipped if the version we're deploying is the same - # as then we're just doing a re-deploy of the same version with potentially different configs. - - name: Download current version for its old bundles - id: current_download - if: steps.current_version.outputs.version != github.ref_name - uses: ./.github/actions/download-verify-element-tarball - with: - tag: v${{ steps.current_version.outputs.version }} - out-file-path: _current_version - - - name: Download target version - uses: ./.github/actions/download-verify-element-tarball - with: - tag: ${{ github.ref_name }} - out-file-path: _deploy - - - name: Merge current bundles into target - if: steps.current_download.outcome == 'success' - run: cp -vnpr _current_version/bundles/* _deploy/bundles/ - - - name: Copy config - run: cp apps/web/element.io/app/config.json _deploy/config.json - - - name: Populate 404.html - run: echo "404 Not Found" > _deploy/404.html - - - name: Populate _headers - run: cp .github/cfp_headers _deploy/_headers - - - name: Wait for other steps to succeed - uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork - if: inputs.skip-checks != true - with: - ref: ${{ github.sha }} - running-workflow-name: "Deploy to Cloudflare Pages" - repo-token: ${{ secrets.GITHUB_TOKEN }} - wait-interval: 10 - check-regexp: ^((?!SonarCloud|SonarQube|issue|board|label|Release|prepare|GitHub Pages).)*$ - - - name: Deploy to Cloudflare Pages - uses: cloudflare/pages-action@f0a1cd58cd66095dee69bfa18fa5efd1dde93bca # v1 - with: - apiToken: ${{ secrets.CF_PAGES_TOKEN }} - accountId: ${{ secrets.CF_PAGES_ACCOUNT_ID }} - projectName: ${{ env.SITE == 'staging.element.io' && 'element-web-staging' || 'element-web' }} - directory: _deploy - gitHubToken: ${{ secrets.GITHUB_TOKEN }} - branch: main diff --git a/.github/workflows/docker.yaml b/.github/workflows/docker.yaml deleted file mode 100644 index cbca8ebdc..000000000 --- a/.github/workflows/docker.yaml +++ /dev/null @@ -1,181 +0,0 @@ -name: Docker -on: - workflow_dispatch: {} - push: - tags: [v*] - pull_request: {} - schedule: - # This job can take a while, and we have usage limits, so just publish develop only twice a day - - cron: "0 7/12 * * *" -concurrency: ${{ github.workflow }}-${{ github.ref_name }} -permissions: {} -jobs: - buildx: - name: Docker Buildx - runs-on: ubuntu-24.04 - environment: ${{ github.event_name != 'pull_request' && 'dockerhub' || '' }} - permissions: - id-token: write # needed for signing the images with GitHub OIDC Token - packages: write # needed for publishing packages to GHCR - env: - TEST_TAG: vectorim/element-web:test - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - fetch-depth: 0 # needed for docker-package to be able to calculate the version - persist-credentials: false - - - name: Install Cosign - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - if: github.event_name != 'pull_request' - - - name: Set up QEMU - uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4 - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4 - with: - install: true - - - name: Build and load - id: test-build - uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7 - with: - context: . - file: apps/web/Dockerfile - load: true - - - name: Test the image - env: - IMAGEID: ${{ steps.test-build.outputs.imageid }} - timeout-minutes: 2 - run: | - set -x - - # Make a fake module to test the image - MODULE_PATH="modules/module_name/index.js" - mkdir -p $(dirname $MODULE_PATH) - echo 'alert("Testing");' > $MODULE_PATH - - # Spin up a container of the image - ELEMENT_WEB_PORT=8181 - CONTAINER_ID=$( - docker run \ - --rm \ - -e "ELEMENT_WEB_PORT=$ELEMENT_WEB_PORT" \ - -dp "$ELEMENT_WEB_PORT:$ELEMENT_WEB_PORT" \ - -v $(pwd)/modules:/modules \ - "$IMAGEID" \ - ) - - # Run some smoke tests - wget --retry-connrefused --tries=5 -q --wait=3 --spider "http://localhost:$ELEMENT_WEB_PORT/modules/module_name/index.js" - MODULE_0=$(curl "http://localhost:$ELEMENT_WEB_PORT/config.json" | jq -r .modules[0]) - test "$MODULE_0" = "/${MODULE_PATH}" - - # Check healthcheck - until test "$(docker inspect -f {{.State.Health.Status}} $CONTAINER_ID)" == "healthy"; do - sleep 1 - done - - # Clean up - docker stop "$CONTAINER_ID" - - - name: Docker meta - id: meta - uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6 - if: github.event_name != 'pull_request' - with: - images: | - vectorim/element-web - ghcr.io/element-hq/element-web - oci-push.vpn.infra.element.io/element-web - tags: | - type=ref,event=branch - type=ref,event=tag - flavor: | - latest=${{ contains(github.ref_name, '-rc.') && 'false' || 'auto' }} - - - name: Login to Docker Hub - uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4 - if: github.event_name != 'pull_request' - with: - username: ${{ secrets.DOCKERHUB_USERNAME }} - password: ${{ secrets.DOCKERHUB_TOKEN }} - - - name: Login to GitHub Container Registry - uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4 - if: github.event_name != 'pull_request' - with: - registry: ghcr.io - username: ${{ github.repository_owner }} - password: ${{ secrets.GITHUB_TOKEN }} - - - name: Connect to Tailscale - uses: tailscale/github-action@306e68a486fd2350f2bfc3b19fcd143891a4a2d8 # v4 - if: github.event_name != 'pull_request' - with: - oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }} - audience: ${{ secrets.TS_AUDIENCE }} - tags: tag:github-actions - - - name: Compute vault jwt role name - id: vault-jwt-role - if: github.event_name != 'pull_request' - run: | - echo "role_name=github_service_management_$( echo "${{ github.repository }}" | sed -r 's|[/-]|_|g')" | tee -a "$GITHUB_OUTPUT" - - - name: Get team registry token - id: import-secrets - uses: hashicorp/vault-action@4c06c5ccf5c0761b6029f56cfb1dcf5565918a3b # v3 - if: github.event_name != 'pull_request' - with: - url: https://vault.infra.ci.i.element.dev - role: ${{ steps.vault-jwt-role.outputs.role_name }} - path: service-management/github-actions - jwtGithubAudience: https://vault.infra.ci.i.element.dev - method: jwt - secrets: | - services/web-repositories/secret/data/oci.element.io username | OCI_USERNAME ; - services/web-repositories/secret/data/oci.element.io password | OCI_PASSWORD ; - - - name: Login to oci.element.io Registry - uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4 - if: github.event_name != 'pull_request' - with: - registry: oci-push.vpn.infra.element.io - username: ${{ steps.import-secrets.outputs.OCI_USERNAME }} - password: ${{ steps.import-secrets.outputs.OCI_PASSWORD }} - - - name: Build and push - id: build-and-push - uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7 - if: github.event_name != 'pull_request' - with: - context: . - file: apps/web/Dockerfile - push: true - platforms: linux/amd64,linux/arm64 - tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} - - - name: Sign the images with GitHub OIDC Token - env: - DIGEST: ${{ steps.build-and-push.outputs.digest }} - TAGS: ${{ steps.meta.outputs.tags }} - if: github.event_name != 'pull_request' - run: | - images="" - for tag in ${TAGS}; do - images+="${tag}@${DIGEST} " - done - cosign sign --yes ${images} - - - name: Update repo description - uses: peter-evans/dockerhub-description@1b9a80c056b620d92cedb9d9b5a223409c68ddfa # v5 - if: github.event_name != 'pull_request' - continue-on-error: true - with: - username: ${{ secrets.DOCKERHUB_USERNAME }} - password: ${{ secrets.DOCKERHUB_TOKEN }} - repository: vectorim/element-web diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml deleted file mode 100644 index 943998991..000000000 --- a/.github/workflows/docs.yml +++ /dev/null @@ -1,55 +0,0 @@ -name: Deploy documentation - -on: - push: - branches: [develop] - workflow_dispatch: {} - -permissions: {} - -concurrency: - group: "pages" - cancel-in-progress: false - -jobs: - build: - name: GitHub Pages - runs-on: ubuntu-24.04 - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - with: - package_json_file: package.json - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - cache: "pnpm" - cache-dependency-path: pnpm-lock.yaml - node-version: "lts/*" - - - name: Fetch layered build - run: ./scripts/layered.sh - - - name: Build docs - run: pnpm run docs:build - - - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5 - with: - path: ./docs/.vitepress/dist - - deploy: - environment: - name: github-pages - url: ${{ steps.deployment.outputs.page_url }} - runs-on: ubuntu-24.04 - permissions: - pages: write - id-token: write - needs: build - steps: - - name: Deploy to GitHub Pages - id: deployment - uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5 diff --git a/.github/workflows/issue_closed.yml b/.github/workflows/issue_closed.yml deleted file mode 100644 index e42d54dc6..000000000 --- a/.github/workflows/issue_closed.yml +++ /dev/null @@ -1,157 +0,0 @@ -# For duplicate issues, ensure the close type is right (not planned), update it if not -# For all closed (completed) issues, cascade the closure onto any referenced rageshakes -# For all closed (not planned) issues, comment on rageshakes to move them into the canonical issue if one exists -on: - issues: - types: [closed] -permissions: {} # We use ELEMENT_BOT_TOKEN instead -jobs: - tidy: - name: Tidy closed issues - runs-on: ubuntu-24.04 - steps: - - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9 - id: main - with: - # PAT needed as the GITHUB_TOKEN won't be able to see cross-references from other orgs (matrix-org) - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - script: | - const variables = { - owner: context.repo.owner, - name: context.repo.repo, - number: context.issue.number, - }; - - const query = `query($owner:String!, $name:String!, $number:Int!) { - repository(owner: $owner, name: $name) { - issue(number: $number) { - stateReason, - timelineItems(first: 100, itemTypes: [MARKED_AS_DUPLICATE_EVENT, UNMARKED_AS_DUPLICATE_EVENT, CROSS_REFERENCED_EVENT]) { - edges { - node { - __typename - ... on MarkedAsDuplicateEvent { - canonical { - ... on Issue { - repository { - nameWithOwner - } - number - } - ... on PullRequest { - repository { - nameWithOwner - } - number - } - } - } - ... on UnmarkedAsDuplicateEvent { - canonical { - ... on Issue { - repository { - nameWithOwner - } - number - } - ... on PullRequest { - repository { - nameWithOwner - } - number - } - } - } - ... on CrossReferencedEvent { - source { - ... on Issue { - repository { - nameWithOwner - } - number - } - ... on PullRequest { - repository { - nameWithOwner - } - number - } - } - } - } - } - } - } - } - }`; - - const result = await github.graphql(query, variables); - const { stateReason, timelineItems: { edges } } = result.repository.issue; - - const RAGESHAKE_OWNER = "matrix-org"; - const RAGESHAKE_REPO = "element-web-rageshakes"; - const rageshakes = new Set(); - const duplicateOf = new Set(); - - console.log("Edges: ", JSON.stringify(edges)); - - for (const { node } of edges) { - switch(node.__typename) { - case "MarkedAsDuplicateEvent": - duplicateOf.add(node.canonical.repository.nameWithOwner + "#" + node.canonical.number); - break; - case "UnmarkedAsDuplicateEvent": - duplicateOf.remove(node.canonical.repository.nameWithOwner + "#" + node.canonical.number); - break; - case "CrossReferencedEvent": - if (node.source.repository.nameWithOwner === (RAGESHAKE_OWNER + "/" + RAGESHAKE_REPO)) { - rageshakes.add(node.source.number); - } - break; - } - } - - console.log("Duplicate of: ", duplicateOf); - console.log("Found rageshakes: ", rageshakes); - - if (duplicateOf.size) { - const body = Array.from(duplicateOf).join("\n"); - - // Comment on all rageshakes to create relationship to the issue this was closed as duplicate of - for (const rageshake of rageshakes) { - github.rest.issues.createComment({ - owner: RAGESHAKE_OWNER, - repo: RAGESHAKE_REPO, - issue_number: rageshake, - body, - }); - } - - // Duplicate was closed with wrong reason, fix it - if (stateReason === "COMPLETED") { - core.setOutput("closeAsNotPlanned", "true"); - } - } else { - // This issue was closed, close all related rageshakes - for (const rageshake of rageshakes) { - github.rest.issues.update({ - owner: RAGESHAKE_OWNER, - repo: RAGESHAKE_REPO, - issue_number: rageshake, - state: "closed", - }); - } - } - - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9 - name: Close duplicate as Not Planned - if: steps.main.outputs.closeAsNotPlanned - with: - # We do this step separately, and with the default token so as to not re-trigger this workflow when re-closing - script: | - await github.graphql(`mutation($id:ID!) { - closeIssue(input: { issueId:$id, stateReason:NOT_PLANNED }) { - clientMutationId - } - }`, { - id: context.payload.issue.node_id, - }); diff --git a/.github/workflows/localazy_download.yaml b/.github/workflows/localazy_download.yaml deleted file mode 100644 index 730c680c7..000000000 --- a/.github/workflows/localazy_download.yaml +++ /dev/null @@ -1,14 +0,0 @@ -name: Localazy Download -on: - workflow_dispatch: {} - schedule: - - cron: "0 6 * * 1,3,5" # Every Monday, Wednesday and Friday at 6am UTC -permissions: - pull-requests: write # needed to auto-approve PRs -jobs: - download: - uses: matrix-org/matrix-web-i18n/.github/workflows/localazy_download.yaml@6eda3835118f3bc3fb658a1a3c20b7da9d16ae42 - with: - packageManager: pnpm - secrets: - ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} diff --git a/.github/workflows/localazy_upload.yaml b/.github/workflows/localazy_upload.yaml deleted file mode 100644 index 6c509bc38..000000000 --- a/.github/workflows/localazy_upload.yaml +++ /dev/null @@ -1,14 +0,0 @@ -name: Localazy Upload -on: - workflow_dispatch: {} - push: - branches: [develop] - paths: - - "apps/web/src/i18n/strings/en_EN.json" - - "packages/shared-components/src/i18n/strings/en_EN.json" -permissions: {} # No permissions needed -jobs: - upload: - uses: matrix-org/matrix-web-i18n/.github/workflows/localazy_upload.yaml@6eda3835118f3bc3fb658a1a3c20b7da9d16ae42 - secrets: - LOCALAZY_WRITE_KEY: ${{ secrets.LOCALAZY_WRITE_KEY }} diff --git a/.github/workflows/merge-queue.yaml b/.github/workflows/merge-queue.yaml deleted file mode 100644 index 1e4d7d3ed..000000000 --- a/.github/workflows/merge-queue.yaml +++ /dev/null @@ -1,29 +0,0 @@ -# Tweaks the behaviour of Merge Queue to skip certain checks -name: Merge Queue tweaks -on: - merge_group: - types: [checks_requested] - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -permissions: {} - -jobs: - run: - runs-on: ubuntu-24.04 - permissions: - statuses: write - steps: - # This is only needed as license/cla at time of writing seems to be extraordinarily flaky - # and Github doesn't support conditional checks between PR & merge queue. - # This is fine to do as a PR won't make it to merge queue until it has license/cla passing. - - name: Skip license/cla on merge queues - uses: guibranco/github-status-action-v2@9bfa8773cdbdc6c185747fd43cd7faa9d7c32f09 - with: - authToken: ${{ secrets.GITHUB_TOKEN }} - state: success - context: license/cla - sha: ${{ github.sha }} - target_url: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }} diff --git a/.github/workflows/netlify.yaml b/.github/workflows/netlify.yaml deleted file mode 100644 index 0aa8372ab..000000000 --- a/.github/workflows/netlify.yaml +++ /dev/null @@ -1,53 +0,0 @@ -# Triggers after the layered build has finished, taking the artifact -# and uploading it to netlify -name: Upload Preview Build to Netlify -on: - # Privilege escalation necessary to publish to Netlify - # 🚨 We must not execute any checked out code here. - workflow_run: # zizmor: ignore[dangerous-triggers] - workflows: ["Build"] - types: - - completed -jobs: - deploy: - if: github.event.workflow_run.conclusion != 'cancelled' && github.event.workflow_run.event == 'pull_request' - runs-on: ubuntu-24.04 - environment: Netlify - permissions: - actions: read - deployments: write - steps: - - name: 📝 Create Deployment - uses: bobheadxi/deployments@648679e8e4915b27893bd7dbc35cb504dc915bc8 # v1 - id: deployment - with: - step: start - token: ${{ secrets.GITHUB_TOKEN }} - env: Netlify - ref: ${{ github.event.workflow_run.head_sha }} - desc: | - Do you trust the author of this PR? Maybe this build will steal your keys or give you malware. - Exercise caution. Use test accounts. - - - name: 📥 Download artifact - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - run-id: ${{ github.event.workflow_run.id }} - name: webapp-ubuntu-24.04 - path: webapp - - - name: 📤 Deploy to Netlify - uses: matrix-org/netlify-pr-preview@9805cd123fc9a7e421e35340a05e1ebc5dee46b5 # v3 - with: - path: webapp - owner: ${{ github.event.workflow_run.head_repository.owner.login }} - branch: ${{ github.event.workflow_run.head_branch }} - revision: ${{ github.event.workflow_run.head_sha }} - token: ${{ secrets.NETLIFY_AUTH_TOKEN }} - site_id: ${{ vars.NETLIFY_SITE_ID }} - deployment_env: ${{ steps.deployment.outputs.env }} - deployment_id: ${{ steps.deployment.outputs.deployment_id }} - desc: | - Do you trust the author of this PR? Maybe this build will steal your keys or give you malware. - Exercise caution. Use test accounts. diff --git a/.github/workflows/npm-publish.yaml b/.github/workflows/npm-publish.yaml deleted file mode 100644 index 55a1f37ed..000000000 --- a/.github/workflows/npm-publish.yaml +++ /dev/null @@ -1,47 +0,0 @@ -name: Publish npm package -run-name: Publish ${{ inputs.package }} -on: - workflow_dispatch: - inputs: - package: - description: Which package to release - required: true - type: choice - options: - - playwright-common - - shared-components - - module-api - -concurrency: release -jobs: - publish: - name: "Publish" - runs-on: ubuntu-latest - permissions: - contents: write - id-token: write - - steps: - - name: 🧮 Checkout code - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - name: 🔧 Set up node environment - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - cache: "pnpm" - node-version-file: ".node-version" - registry-url: "https://registry.npmjs.org" - - # Ensure npm 11.5.1 or later is installed - - name: Update npm - run: npm install -g npm@latest - - - name: 🛠️ Install dependencies - run: pnpm install --frozen-lockfile - - - name: 🚀 Publish to npm - working-directory: packages/${{ inputs.package }} - run: npm publish --access public --provenance diff --git a/.github/workflows/pull_request.yaml b/.github/workflows/pull_request.yaml deleted file mode 100644 index 129bcea0e..000000000 --- a/.github/workflows/pull_request.yaml +++ /dev/null @@ -1,16 +0,0 @@ -name: Pull Request -on: - # Privilege escalation necessary access members of the review teams - # 🚨 We must not execute any checked out code here, and be careful around use of user-controlled inputs. - pull_request_target: # zizmor: ignore[dangerous-triggers] - types: [opened, edited, labeled, unlabeled, synchronize] - merge_group: - types: [checks_requested] -permissions: {} -jobs: - action: - uses: matrix-org/matrix-js-sdk/.github/workflows/pull_request.yaml@develop # zizmor: ignore[unpinned-uses] - permissions: - pull-requests: write - secrets: - ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} diff --git a/.github/workflows/pull_request_base_branch.yaml b/.github/workflows/pull_request_base_branch.yaml deleted file mode 100644 index 32c79071e..000000000 --- a/.github/workflows/pull_request_base_branch.yaml +++ /dev/null @@ -1,17 +0,0 @@ -name: Pull Request Base Branch -on: - pull_request: - types: [opened, edited, synchronize] -permissions: {} # No permissions required -jobs: - check_base_branch: - name: Check PR base branch - runs-on: ubuntu-24.04 - steps: - - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9 - with: - script: | - const baseBranch = context.payload.pull_request.base.ref; - if (!['develop', 'staging'].includes(baseBranch) && !baseBranch.startsWith('feat/')) { - core.setFailed(`Invalid base branch: ${baseBranch}`); - } diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml deleted file mode 100644 index a574539f7..000000000 --- a/.github/workflows/release-drafter.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: Release Drafter -on: - push: - branches: [staging] - workflow_dispatch: {} -concurrency: ${{ github.workflow }} -permissions: {} -jobs: - draft: - permissions: - contents: write - uses: matrix-org/matrix-js-sdk/.github/workflows/release-drafter-workflow.yml@develop # zizmor: ignore[unpinned-uses] diff --git a/.github/workflows/release-gitflow.yml b/.github/workflows/release-gitflow.yml deleted file mode 100644 index 7985ba20d..000000000 --- a/.github/workflows/release-gitflow.yml +++ /dev/null @@ -1,17 +0,0 @@ -# Gitflow merge-back master->develop -name: Merge master -> develop -on: - push: - branches: [master] -concurrency: ${{ github.repository }}-${{ github.workflow }} -permissions: {} # We use ELEMENT_BOT_TOKEN instead -jobs: - merge: - uses: matrix-org/matrix-js-sdk/.github/workflows/release-gitflow.yml@develop # zizmor: ignore[unpinned-uses] - secrets: - ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} - with: - # This relates to the directory in which to reset dependencies, only web needs this - dir: apps/web - dependencies: | - matrix-js-sdk diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml deleted file mode 100644 index b1a81af77..000000000 --- a/.github/workflows/release.yml +++ /dev/null @@ -1,68 +0,0 @@ -name: Release Process -on: - workflow_dispatch: - inputs: - mode: - description: What type of release - required: true - default: rc - type: choice - options: - - rc - - final -concurrency: ${{ github.workflow }} -permissions: {} -jobs: - release: - uses: matrix-org/matrix-js-sdk/.github/workflows/release-make.yml@develop # zizmor: ignore[unpinned-uses] - permissions: - contents: write - issues: write - pull-requests: read - id-token: write - secrets: - ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} - GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} - GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} - with: - final: ${{ inputs.mode == 'final' }} - gpg-fingerprint: ${{ vars.GPG_FINGERPRINT }} - asset-path: dist/*.tar.gz - expected-asset-count: 3 - # Desktop has no dist script so we only target web here - dist-dir: apps/web - version-dirs: apps/web apps/desktop - - check: - name: Post release checks - needs: release - runs-on: ubuntu-24.04 - permissions: - checks: read - steps: - - name: Wait for docker build - uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork - with: - ref: master - repo-token: ${{ secrets.GITHUB_TOKEN }} - wait-interval: 10 - check-name: "Docker Buildx" - allowed-conclusions: success - - - name: Wait for debian package - uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork - with: - ref: master - repo-token: ${{ secrets.GITHUB_TOKEN }} - wait-interval: 10 - check-name: Build package - allowed-conclusions: success - - - name: Wait for desktop packaging - uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork - with: - ref: master - repo-token: ${{ secrets.GITHUB_TOKEN }} - wait-interval: 10 - check-regexp: Prepare|Linux|macOS|Windows|Deploy|deploy - allowed-conclusions: success diff --git a/.github/workflows/release_prepare.yml b/.github/workflows/release_prepare.yml deleted file mode 100644 index cbe464d17..000000000 --- a/.github/workflows/release_prepare.yml +++ /dev/null @@ -1,97 +0,0 @@ -name: Cut branches -on: - workflow_dispatch: - inputs: - element-web: - description: Prepare element-web - required: true - type: boolean - default: true - matrix-js-sdk: - description: Prepare matrix-js-sdk - required: true - type: boolean - default: true -permissions: {} # Uses ELEMENT_BOT_TOKEN instead -jobs: - checks: - name: Sanity checks - strategy: - matrix: - repo: - - matrix-org/matrix-js-sdk - - element-hq/element-web - uses: matrix-org/matrix-js-sdk/.github/workflows/release-checks.yml@develop # zizmor: ignore[unpinned-uses] - secrets: - ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} - with: - repository: ${{ matrix.repo }} - - prepare: - runs-on: ubuntu-24.04 - needs: checks - env: - # The order is specified bottom-up to avoid any races for allchange - REPOS: matrix-js-sdk element-web - steps: - - name: Checkout Element Web - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - if: inputs.element-web - with: - repository: element-hq/element-web - path: element-web - ref: staging - fetch-depth: 0 - fetch-tags: true - token: ${{ secrets.ELEMENT_BOT_TOKEN }} - persist-credentials: true - - name: Checkout Matrix JS SDK - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - if: inputs.matrix-js-sdk - with: - repository: matrix-org/matrix-js-sdk - path: matrix-js-sdk - ref: staging - fetch-depth: 0 - fetch-tags: true - token: ${{ secrets.ELEMENT_BOT_TOKEN }} - persist-credentials: true - - - name: Prepare Git - run: | - git config --global user.email "releases@riot.im" - git config --global user.name "RiotRobot" - - - name: Merge Element Web - if: inputs.element-web - run: | - git -C "element-web" merge origin/develop - - name: Merge JS SDK - if: inputs.matrix-js-sdk - run: | - git -C "matrix-js-sdk" merge origin/develop - - - name: Push staging - run: for REPO in $REPOS; do [ -d "$REPO" ] && git -C "$REPO" push origin staging; done - - - name: Wait for matrix-js-sdk draft - if: inputs.matrix-js-sdk - uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork - with: - ref: staging - repo: matrix-org/matrix-js-sdk - repo-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - wait-interval: 10 - check-name: "draft / draft" - allowed-conclusions: success - - - name: Wait for element-web draft - if: inputs.element-web - uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork - with: - ref: staging - repo: element-hq/element-web - repo-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - wait-interval: 10 - check-name: "draft / draft" - allowed-conclusions: success diff --git a/.github/workflows/shared-component-storybook-build.yml b/.github/workflows/shared-component-storybook-build.yml deleted file mode 100644 index 13b16a239..000000000 --- a/.github/workflows/shared-component-storybook-build.yml +++ /dev/null @@ -1,38 +0,0 @@ -name: Build shared component storybook -on: - merge_group: {} - pull_request: {} - workflow_call: {} - -permissions: {} - -jobs: - doc: - name: Build storybook - runs-on: ubuntu-latest - steps: - - name: 🧮 Checkout code - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - name: 🔧 Pnpm cache - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - cache: "pnpm" - node-version-file: package.json - - - name: 🔨 Install dependencies - working-directory: packages/shared-components - run: "pnpm install --frozen-lockfile" - - - name: 📖 Build Storybook - working-directory: packages/shared-components - run: pnpm build:storybook - - - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: shared-components-storybook - path: packages/shared-components/storybook-static - retention-days: 1 diff --git a/.github/workflows/shared-component-storybook-publish.yaml b/.github/workflows/shared-component-storybook-publish.yaml deleted file mode 100644 index 1a365c6b6..000000000 --- a/.github/workflows/shared-component-storybook-publish.yaml +++ /dev/null @@ -1,33 +0,0 @@ -name: Publish shared component storybook -on: - workflow_dispatch: {} - push: - branches: - - "develop" - paths: - - "packages/shared-components/**/*" - -permissions: {} - -jobs: - build: - name: Build storybook - uses: ./.github/workflows/shared-component-storybook-build.yml - - publish: - name: Publish storybook - runs-on: ubuntu-latest - needs: build - environment: SharedComponents - steps: - - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - name: shared-components-storybook - path: storybook-static - - - name: 🚀 Deploy to Cloudflare Pages - uses: cloudflare/wrangler-action@9acf94ace14e7dc412b076f2c5c20b8ce93c79cd # v3 - with: - apiToken: ${{ secrets.CF_PAGES_TOKEN }} - accountId: ${{ secrets.CF_PAGES_ACCOUNT_ID }} - command: pages deploy storybook-static --project-name=shared-components-storybook diff --git a/.github/workflows/shared-component-visual-tests-netlify.yaml b/.github/workflows/shared-component-visual-tests-netlify.yaml deleted file mode 100644 index a1aa61b02..000000000 --- a/.github/workflows/shared-component-visual-tests-netlify.yaml +++ /dev/null @@ -1,50 +0,0 @@ -# Triggers after the shared component tests have finished, -# It uploads the received images and diffs to netlify, printing the URLs to the console -name: Upload Shared Component Visual Test Diffs -on: - # Privilege escalation necessary to deploy to Netlify - # 🚨 We must not execute any checked out code here. - workflow_run: # zizmor: ignore[dangerous-triggers] - workflows: ["Shared Component Visual Tests"] - types: - - completed - -concurrency: - group: ${{ github.workflow }}-${{ github.event.workflow_run.head_branch || github.run_id }} - cancel-in-progress: ${{ github.event.workflow_run.event == 'pull_request' }} - -permissions: {} - -jobs: - report: - if: github.event.workflow_run.conclusion == 'failure' - name: Upload Diffs - runs-on: ubuntu-24.04 - environment: Netlify - permissions: - actions: read - deployments: write - steps: - - name: Download Diffs - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - run-id: ${{ github.event.workflow_run.id }} - name: received-images - path: received-images - - - name: Generate Index - run: "cd received-images && tree -L 1 --noreport -H '' -o index.html ." - - - name: 📤 Deploy to Netlify - uses: matrix-org/netlify-pr-preview@9805cd123fc9a7e421e35340a05e1ebc5dee46b5 # v3 - with: - path: received-images - owner: ${{ github.event.workflow_run.head_repository.owner.login }} - branch: ${{ github.event.workflow_run.head_branch }} - revision: ${{ github.event.workflow_run.head_sha }} - token: ${{ secrets.NETLIFY_AUTH_TOKEN }} - site_id: ${{ vars.NETLIFY_SITE_ID }} - desc: Shared Component Visual Diffs - deployment_env: SharedComponentDiffs - prefix: "diffs-" diff --git a/.github/workflows/shared-component-visual-tests.yaml b/.github/workflows/shared-component-visual-tests.yaml deleted file mode 100644 index 6755197ee..000000000 --- a/.github/workflows/shared-component-visual-tests.yaml +++ /dev/null @@ -1,60 +0,0 @@ -name: Shared Component Visual Tests -on: - pull_request: {} - merge_group: - types: [checks_requested] - push: - branches: [develop, master] - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -permissions: {} # No permissions required - -jobs: - testStorybook: - name: "Run Visual Tests" - runs-on: ubuntu-24.04 - permissions: - actions: read - issues: read - pull-requests: read - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - repository: element-hq/element-web - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - cache: "pnpm" - node-version: "lts/*" - - - name: Install dependencies - working-directory: packages/shared-components - run: pnpm install --frozen-lockfile - - - name: Setup playwright - uses: ./.github/actions/setup-playwright - with: - write-cache: ${{ github.event_name != 'merge_group' }} - - - name: Run Visual tests - working-directory: packages/shared-components - run: "pnpm test:storybook --run" - - - name: Detect stale screenshots - run: | - if diff -rq __baselines__ __results__ | grep "^Only in __baselines__"; then - exit 1 - fi - working-directory: packages/shared-components/__vis__/linux - - - name: Upload received images & diffs - if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: received-images - path: packages/shared-components/__vis__/linux diff --git a/.github/workflows/sonarqube.yml b/.github/workflows/sonarqube.yml deleted file mode 100644 index e934f05ad..000000000 --- a/.github/workflows/sonarqube.yml +++ /dev/null @@ -1,27 +0,0 @@ -name: SonarQube -on: - # Privilege escalation necessary to call upon SonarCloud - # 🚨 We must not execute any checked out code here. - workflow_run: # zizmor: ignore[dangerous-triggers] - workflows: ["Tests"] - types: - - completed -concurrency: - group: ${{ github.workflow }}-${{ github.event.workflow_run.head_branch }} - cancel-in-progress: true -permissions: {} -jobs: - sonarqube: - name: 🩻 SonarQube - if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event != 'merge_group' - uses: matrix-org/matrix-js-sdk/.github/workflows/sonarcloud.yml@develop # zizmor: ignore[unpinned-uses] - permissions: - actions: read - statuses: write - id-token: write # sonar - secrets: - SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} - ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} - with: - sharded: true - version-pkg-json-dir: ./apps/web diff --git a/.github/workflows/static_analysis.yaml b/.github/workflows/static_analysis.yaml deleted file mode 100644 index 895ea83dc..000000000 --- a/.github/workflows/static_analysis.yaml +++ /dev/null @@ -1,133 +0,0 @@ -name: Static Analysis -on: - pull_request: {} - push: - branches: [develop, master] - merge_group: - types: [checks_requested] -concurrency: - group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -env: - # This must be set for fetchdep.sh to get the right branch - PR_NUMBER: ${{ github.event.pull_request.number }} - NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes - -permissions: {} # No permissions required - -jobs: - lint: - strategy: - fail-fast: false - matrix: - include: - - name: Typescript Syntax Check - install: layered - command: "lint:types" - - name: Prettier - install: normal - command: "lint:prettier" - - name: ESLint - install: normal - command: "lint:js" - - name: Style Lint - install: normal - command: "lint:style" - - name: Workflow Lint - install: normal - command: "lint:workflows" - - name: Analyse Dead Code - install: normal - command: "lint:knip" - - name: Rethemendex Check - command: "rethemendex" - assert-diff: true - - name: Docs - install: layered - command: "docs:build" - name: ${{ matrix.name }} - runs-on: ubuntu-24.04 - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - if: matrix.install != '' - with: - cache: "pnpm" - node-version: "lts/*" - - - name: Install Dependencies (layered) - if: matrix.install == 'layered' - run: "./scripts/layered.sh" - - name: Install Dependencies (normal) - if: matrix.install == 'normal' - run: "pnpm install --frozen-lockfile" - - - name: Run ${{ matrix.command }} - run: pnpm --if-present run "$CMD" && pnpm -r --if-present run "$CMD" - env: - CMD: ${{ matrix.command }} - - - name: Assert no changes - run: git diff --exit-code - if: matrix.assert-diff - - zizmor: - name: Zizmor Github Actions lint - runs-on: ubuntu-24.04 - permissions: - security-events: write - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - name: Run zizmor - uses: zizmorcore/zizmor-action@b1d7e1fb5de872772f31590499237e7cce841e8e # v0.5.3 - - i18n: - strategy: - fail-fast: false - matrix: - include: - - name: Element Web - path: "apps/web" - allowed-hardcoded-keys: | - console_dev_note - labs|element_call_video_rooms - labs|feature_disable_call_per_sender_encryption - voip|element_call - error|invalid_json - error|misconfigured - welcome|title_element - devtools|settings|elementCallUrl - labs|sliding_sync_description - settings|voip|noise_suppression_description - settings|voip|echo_cancellation_description - - name: Element Desktop - path: "apps/desktop" - - name: Shared Components - path: "packages/shared-components" - name: "i18n Check (${{ matrix.name }})" - uses: matrix-org/matrix-web-i18n/.github/workflows/i18n_check.yml@6eda3835118f3bc3fb658a1a3c20b7da9d16ae42 - permissions: - pull-requests: read - with: - hardcoded-words: "Element" - packageManager: pnpm - path: ${{ matrix.path }} - allowed-hardcoded-keys: ${{ matrix.allowed-hardcoded-keys }} - - # Dummy job to simplify branch protections - ci: - name: Static Analysis - needs: [lint, i18n, zizmor] - if: always() - runs-on: ubuntu-24.04 - steps: - - if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') - run: exit 1 diff --git a/.github/workflows/sync-labels.yml b/.github/workflows/sync-labels.yml deleted file mode 100644 index a92fbe6fd..000000000 --- a/.github/workflows/sync-labels.yml +++ /dev/null @@ -1,24 +0,0 @@ -name: Sync labels -on: - workflow_dispatch: {} - schedule: - - cron: "0 1 * * *" # 1am every day - push: - branches: - - develop - paths: - - .github/labels.yml - -permissions: {} # We use ELEMENT_BOT_TOKEN instead - -jobs: - sync-labels: - uses: element-hq/element-meta/.github/workflows/sync-labels.yml@7f2f93fb9b52ece7a0998f60e64862aa203c1746 - with: - LABELS: | - element-hq/element-meta - .github/labels.yml - DELETE: true - WET: true - secrets: - ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml deleted file mode 100644 index 332798676..000000000 --- a/.github/workflows/tests.yml +++ /dev/null @@ -1,188 +0,0 @@ -name: Tests -on: - pull_request: {} - merge_group: - types: [checks_requested] - push: - branches: [develop, master] - workflow_call: - inputs: - disable_coverage: - type: boolean - required: false - description: "Specify true to skip generating and uploading coverage for tests" - matrix-js-sdk-sha: - type: string - required: false - description: "The matrix-js-sdk SHA to use" -concurrency: - group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -env: - ENABLE_COVERAGE: ${{ github.event_name != 'merge_group' && inputs.disable_coverage != 'true' }} - # fetchdep.sh needs to know our PR number - PR_NUMBER: ${{ github.event.pull_request.number }} - NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes - -permissions: {} - -jobs: - jest_ew: - name: Jest (Element Web) - runs-on: ubuntu-24.04 - strategy: - fail-fast: false - matrix: - # Run multiple instances in parallel to speed up the tests - runner: [1, 2] - steps: - - name: Checkout code - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - repository: ${{ inputs.matrix-js-sdk-sha && 'element-hq/element-web' || github.repository }} - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - name: pnpm cache - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - node-version: "lts/*" - cache: "pnpm" - - - name: Install Deps - run: "./scripts/layered.sh" - env: - JS_SDK_GITHUB_BASE_REF: ${{ inputs.matrix-js-sdk-sha }} - - - name: Jest Cache - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5 - with: - path: /tmp/jest_cache - key: ${{ hashFiles('**/pnpm-lock.yaml') }} - - - name: Get number of CPU cores - id: cpu-cores - uses: SimenB/github-actions-cpu-cores@97330871fe1b7d3529392ea000e3d2c4b357e403 # v3 - - - name: Run tests - working-directory: apps/web - run: | - pnpm test \ - --coverage=$ENABLE_COVERAGE \ - --ci \ - --max-workers $MAX_WORKERS \ - --shard "$SHARD" \ - --cacheDirectory /tmp/jest_cache - env: - JEST_SONAR_UNIQUE_OUTPUT_NAME: true - - # tell jest to use coloured output - FORCE_COLOR: true - MAX_WORKERS: ${{ steps.cpu-cores.outputs.count }} - SHARD: ${{ format('{0}/{1}', matrix.runner, strategy.job-total) }} - - - name: Move coverage files into place - if: env.ENABLE_COVERAGE == 'true' - working-directory: apps/web - run: mv coverage/lcov.info coverage/$NODE_VERSION-${{ matrix.runner }}.lcov.info - env: - NODE_VERSION: ${{ steps.setupNode.outputs.node-version }} - - - name: Upload Artifact - if: env.ENABLE_COVERAGE == 'true' - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: coverage-jest-${{ matrix.runner }} - path: | - apps/web/coverage - !apps/web/coverage/lcov-report - - complete: - name: jest-tests - needs: [jest_ew, vitest] - if: always() - runs-on: ubuntu-24.04 - permissions: - statuses: write - steps: - - if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') - run: exit 1 - - - name: Skip SonarCloud in merge queue - if: github.event_name == 'merge_group' || inputs.disable_coverage == 'true' - uses: guibranco/github-status-action-v2@9bfa8773cdbdc6c185747fd43cd7faa9d7c32f09 - with: - authToken: ${{ secrets.GITHUB_TOKEN }} - state: success - description: SonarCloud skipped - context: SonarCloud Code Analysis - sha: ${{ github.sha }} - target_url: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }} - - vitest: - name: Vitest - strategy: - matrix: - path: - - apps/desktop - - packages/shared-components - - packages/module-api - runs-on: ubuntu-24.04 - steps: - - name: Checkout code - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - repository: ${{ inputs.matrix-js-sdk-sha && 'element-hq/element-web' || github.repository }} - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - name: pnpm cache - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - node-version: "lts/*" - cache: "pnpm" - - - name: Install Deps - run: "pnpm install" - - - name: Cache storybook & vitest - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5 - with: - path: | - ${{ matrix.path }}/node_modules/.cache - ${{ matrix.path }}/node_modules/.vite/vitest - key: ${{ matrix.path }}-${{ hashFiles('pnpm-lock.yaml') }} - - - name: Setup playwright - uses: ./.github/actions/setup-playwright - if: matrix.path == 'packages/shared-components' - with: - write-cache: ${{ github.event_name != 'merge_group' }} - - - name: Run tests - working-directory: ${{ matrix.path }} - run: pnpm test:unit --coverage=$ENABLE_COVERAGE - - # Dump the disk usage on failure, because this job seems to fail with disk fills sometimes - - name: df - run: df -h && df -i - if: ${{ failure() }} - - - name: Calculate artifact name - if: env.ENABLE_COVERAGE == 'true' - id: artifact - run: | - NAME=$(basename "$MATRIX_PATH") - echo "name=$NAME" >> $GITHUB_OUTPUT - env: - MATRIX_PATH: ${{ matrix.path }} - - - name: Upload Artifact - if: env.ENABLE_COVERAGE == 'true' - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 - with: - name: coverage-${{ steps.artifact.outputs.name }} - path: | - ${{ matrix.path }}/coverage - !${{ matrix.path }}/coverage/lcov-report diff --git a/.github/workflows/triage-assigned.yml b/.github/workflows/triage-assigned.yml deleted file mode 100644 index 93545e74e..000000000 --- a/.github/workflows/triage-assigned.yml +++ /dev/null @@ -1,21 +0,0 @@ -name: Move issued assigned to specific team members to their boards - -on: - issues: - types: [assigned] - -permissions: {} # We use ELEMENT_BOT_TOKEN instead - -jobs: - web-app-team: - runs-on: ubuntu-24.04 - if: | - contains(github.event.issue.assignees.*.login, 't3chguy') || - contains(github.event.issue.assignees.*.login, 'florianduros') || - contains(github.event.issue.assignees.*.login, 'dbkr') || - contains(github.event.issue.assignees.*.login, 'MidhunSureshR') - steps: - - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: https://github.com/orgs/element-hq/projects/67 - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} diff --git a/.github/workflows/triage-incoming.yml b/.github/workflows/triage-incoming.yml deleted file mode 100644 index 508a8c51d..000000000 --- a/.github/workflows/triage-incoming.yml +++ /dev/null @@ -1,16 +0,0 @@ -name: Move new issues into Issue triage board - -on: - issues: - types: [opened] - -permissions: {} # We use ELEMENT_BOT_TOKEN instead - -jobs: - automate-project-columns: - runs-on: ubuntu-24.04 - steps: - - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: https://github.com/orgs/element-hq/projects/120 - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} diff --git a/.github/workflows/triage-labelled.yml b/.github/workflows/triage-labelled.yml deleted file mode 100644 index 3f56e9f78..000000000 --- a/.github/workflows/triage-labelled.yml +++ /dev/null @@ -1,178 +0,0 @@ -name: Move labelled issues to correct projects - -on: - issues: - types: [labeled] - workflow_call: - secrets: - ELEMENT_BOT_TOKEN: - required: true - -permissions: {} # We use ELEMENT_BOT_TOKEN instead - -jobs: - apply_Z-Labs_label: - name: Add Z-Labs label for features behind labs flags - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'A-Maths') || - contains(github.event.issue.labels.*.name, 'A-Location-Sharing') || - contains(github.event.issue.labels.*.name, 'Z-IA') || - contains(github.event.issue.labels.*.name, 'A-Jump-To-Date ') || - contains(github.event.issue.labels.*.name, 'A-Themes-Custom') || - contains(github.event.issue.labels.*.name, 'A-E2EE-Dehydration') || - contains(github.event.issue.labels.*.name, 'A-Tags') || - contains(github.event.issue.labels.*.name, 'A-Video-Rooms') || - contains(github.event.issue.labels.*.name, 'A-Message-Starring') || - contains(github.event.issue.labels.*.name, 'A-Rich-Text-Editor') || - contains(github.event.issue.labels.*.name, 'A-Element-Call') - steps: - - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9 - with: - script: | - github.rest.issues.addLabels({ - issue_number: context.issue.number, - owner: context.repo.owner, - repo: context.repo.repo, - labels: ['Z-Labs'] - }) - - apply_Help-Wanted_label: - name: Add "Help Wanted" label to all "good first issue" and Hacktoberfest - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'good first issue') || - contains(github.event.issue.labels.*.name, 'Hacktoberfest') - steps: - - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9 - with: - script: | - github.rest.issues.addLabels({ - issue_number: context.issue.number, - owner: context.repo.owner, - repo: context.repo.repo, - labels: ['Help Wanted'] - }) - - move_needs_info_issues: - name: X-Needs-Info issues to Need info column on triage board - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'X-Needs-Info') - steps: - - id: add_to_project - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: ${{ env.PROJECT_URL }} - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - - - id: set_fields - uses: titoportas/update-project-fields@421a54430b3cdc9eefd8f14f9ce0142ab7678751 # v0.1.0 - with: - project-url: ${{ env.PROJECT_URL }} - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - item-id: ${{ steps.add_to_project.outputs.itemId }} # Use the item-id output of the previous step - field-keys: Status - field-values: "Needs info" - env: - PROJECT_URL: https://github.com/orgs/element-hq/projects/120 - - move_flakey_test_issues: - name: Z-Flaky-Test issues to Sized for maintainer column on triage board - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'Z-Flaky-Test') - steps: - - id: add_to_project - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: ${{ env.PROJECT_URL }} - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - - - id: set_fields - uses: titoportas/update-project-fields@421a54430b3cdc9eefd8f14f9ce0142ab7678751 # v0.1.0 - with: - project-url: ${{ env.PROJECT_URL }} - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - item-id: ${{ steps.add_to_project.outputs.itemId }} # Use the item-id output of the previous step - field-keys: Status - field-values: "Sized for maintainer" - env: - PROJECT_URL: https://github.com/orgs/element-hq/projects/120 - - add_priority_design_issues_to_project: - name: P1 X-Needs-Design to Design project board - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'X-Needs-Design') && - (contains(github.event.issue.labels.*.name, 'S-Critical') && - (contains(github.event.issue.labels.*.name, 'O-Frequent') || - contains(github.event.issue.labels.*.name, 'O-Occasional')) || - contains(github.event.issue.labels.*.name, 'S-Major') && - contains(github.event.issue.labels.*.name, 'O-Frequent') || - contains(github.event.issue.labels.*.name, 'A11y')) - steps: - - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: https://github.com/orgs/element-hq/projects/18 - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - - add_product_issues: - name: X-Needs-Product to product project board - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'X-Needs-Product') - steps: - - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: https://github.com/orgs/element-hq/projects/28 - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - - Search_issues_to_board: - name: Search issues to project board - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'A-New-Search-Experience') - steps: - - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: https://github.com/orgs/element-hq/projects/48 - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - - voip: - name: Add labelled issues to VoIP project board - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'Team: VoIP') - steps: - - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: https://github.com/orgs/element-hq/projects/41 - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - - crypto: - name: Add labelled issues to Crypto project - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'Team: Crypto') - steps: - - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: https://github.com/orgs/element-hq/projects/76 - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - - tech_debt: - name: Add labelled issues to tech debt project - runs-on: ubuntu-24.04 - if: > - contains(github.event.issue.labels.*.name, 'A-Developer-Experience') || - contains(github.event.issue.labels.*.name, 'A-Documentation') || - contains(github.event.issue.labels.*.name, 'A-Packaging') || - contains(github.event.issue.labels.*.name, 'A-Technical-Debt') || - contains(github.event.issue.labels.*.name, 'A-Testing') || - contains(github.event.issue.labels.*.name, 'Z-Flaky-Test') - steps: - - uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0 - with: - project-url: https://github.com/orgs/element-hq/projects/101 - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} diff --git a/.github/workflows/triage-move-review-requests.yml b/.github/workflows/triage-move-review-requests.yml deleted file mode 100644 index 6933233c0..000000000 --- a/.github/workflows/triage-move-review-requests.yml +++ /dev/null @@ -1,140 +0,0 @@ -name: Move pull requests asking for review to the relevant project -on: - pull_request_target: - types: [review_requested] - -permissions: {} # Uses ELEMENT_BOT_TOKEN instead -jobs: - add_design_pr_to_project: - name: Move PRs asking for design review to the design board - runs-on: ubuntu-24.04 - steps: - - uses: octokit/graphql-action@ddde8ebb2493e79f390e6449c725c21663a67505 # v3.0.2 - id: find_team_members - with: - headers: '{"GraphQL-Features": "projects_next_graphql"}' - query: | - query find_team_members($team: String!) { - organization(login: "element-hq") { - team(slug: $team) { - members { - nodes { - login - } - } - } - } - } - team: ${{ env.TEAM }} - env: - TEAM: "design" - GITHUB_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} - - id: any_matching_reviewers - run: | - # Fetch requested reviewers, and people who are on the team - echo '${{ tojson(fromjson(steps.find_team_members.outputs.data).organization.team.members.nodes[*].login) }}' | tee /tmp/team_members.json - echo '${{ tojson(github.event.pull_request.requested_reviewers[*].login) }}' | tee /tmp/reviewers.json - jq --raw-output .[] < /tmp/team_members.json | sort | tee /tmp/team_members.txt - jq --raw-output .[] < /tmp/reviewers.json | sort | tee /tmp/reviewers.txt - - # Fetch requested team reviewers, and the name of the team - echo '${{ tojson(github.event.pull_request.requested_teams[*].slug) }}' | tee /tmp/team_reviewers.json - jq --raw-output .[] < /tmp/team_reviewers.json | sort | tee /tmp/team_reviewers.txt - echo '${{ env.TEAM }}' | tee /tmp/team.txt - - # If either a reviewer matches a team member, or a team matches our team, say "true" - if [ $(join /tmp/team_members.txt /tmp/reviewers.txt | wc -l) != 0 ]; then - echo "match=true" >> $GITHUB_OUTPUT - elif [ $(join /tmp/team.txt /tmp/team_reviewers.txt | wc -l) != 0 ]; then - echo "match=true" >> $GITHUB_OUTPUT - else - echo "match=false" >> $GITHUB_OUTPUT - fi - env: - TEAM: "design" - - uses: octokit/graphql-action@ddde8ebb2493e79f390e6449c725c21663a67505 # v3.0.2 - id: add_to_project - if: steps.any_matching_reviewers.outputs.match == 'true' - with: - headers: '{"GraphQL-Features": "projects_next_graphql"}' - query: | - mutation add_to_project($projectid:ID!, $contentid:ID!) { - addProjectV2ItemById(input: {projectId: $projectid contentId: $contentid}) { - item { - id - } - } - } - projectid: ${{ env.PROJECT_ID }} - contentid: ${{ github.event.pull_request.node_id }} - env: - PROJECT_ID: "PVT_kwDOAM0swc0sUA" - TEAM: "design" - GITHUB_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} - - add_product_pr_to_project: - name: Move PRs asking for design review to the design board - runs-on: ubuntu-24.04 - steps: - - uses: octokit/graphql-action@ddde8ebb2493e79f390e6449c725c21663a67505 # v3.0.2 - id: find_team_members - with: - headers: '{"GraphQL-Features": "projects_next_graphql"}' - query: | - query find_team_members($team: String!) { - organization(login: "element-hq") { - team(slug: $team) { - members { - nodes { - login - } - } - } - } - } - team: ${{ env.TEAM }} - env: - TEAM: "product" - GITHUB_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} - - id: any_matching_reviewers - run: | - # Fetch requested reviewers, and people who are on the team - echo '${{ tojson(fromjson(steps.find_team_members.outputs.data).organization.team.members.nodes[*].login) }}' | tee /tmp/team_members.json - echo '${{ tojson(github.event.pull_request.requested_reviewers[*].login) }}' | tee /tmp/reviewers.json - jq --raw-output .[] < /tmp/team_members.json | sort | tee /tmp/team_members.txt - jq --raw-output .[] < /tmp/reviewers.json | sort | tee /tmp/reviewers.txt - - # Fetch requested team reviewers, and the name of the team - echo '${{ tojson(github.event.pull_request.requested_teams[*].slug) }}' | tee /tmp/team_reviewers.json - jq --raw-output .[] < /tmp/team_reviewers.json | sort | tee /tmp/team_reviewers.txt - echo '${{ env.TEAM }}' | tee /tmp/team.txt - - # If either a reviewer matches a team member, or a team matches our team, say "true" - if [ $(join /tmp/team_members.txt /tmp/reviewers.txt | wc -l) != 0 ]; then - echo "match=true" >> $GITHUB_OUTPUT - elif [ $(join /tmp/team.txt /tmp/team_reviewers.txt | wc -l) != 0 ]; then - echo "match=true" >> $GITHUB_OUTPUT - else - echo "match=false" >> $GITHUB_OUTPUT - fi - env: - TEAM: "product" - - uses: octokit/graphql-action@ddde8ebb2493e79f390e6449c725c21663a67505 # v3.0.2 - id: add_to_project - if: steps.any_matching_reviewers.outputs.match == 'true' - with: - headers: '{"GraphQL-Features": "projects_next_graphql"}' - query: | - mutation add_to_project($projectid:ID!, $contentid:ID!) { - addProjectV2ItemById(input: {projectId: $projectid contentId: $contentid}) { - item { - id - } - } - } - projectid: ${{ env.PROJECT_ID }} - contentid: ${{ github.event.pull_request.node_id }} - env: - PROJECT_ID: "PVT_kwDOAM0swc4AAg6N" - TEAM: "product" - GITHUB_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }} diff --git a/.github/workflows/triage-stale.yml b/.github/workflows/triage-stale.yml deleted file mode 100644 index bd2df0a56..000000000 --- a/.github/workflows/triage-stale.yml +++ /dev/null @@ -1,29 +0,0 @@ -name: Close stale issues & PRs -on: - workflow_dispatch: {} - schedule: - - cron: "30 1 * * *" -permissions: {} -jobs: - close: - runs-on: ubuntu-24.04 - permissions: - actions: write - issues: write - pull-requests: write - steps: - - uses: actions/stale@b5d41d4e1d5dceea10e7104786b73624c18a190f # v10 - with: - operations-per-run: 100 - - # Flaky test issue closing - any-of-issue-labels: "Z-Flaky-Test-Chrome,Z-Flaky-Test-Firefox,Z-Flaky-Test-Webkit" - days-before-issue-stale: 14 - days-before-issue-close: 0 - close-issue-message: "This flaky test issue has not been updated in 14 days. It is being closed as presumed resolved." - exempt-issue-labels: "Z-Flaky-Test-Disabled" - - # Stale PR closing - days-before-pr-stale: 180 - days-before-pr-close: 0 - close-pr-message: "This PR has been automatically closed because it has been stale for 180 days. If you wish to continue working on this PR, please ping a maintainer to reopen it." diff --git a/.github/workflows/triage-unlabelled.yml b/.github/workflows/triage-unlabelled.yml deleted file mode 100644 index 04f312ab3..000000000 --- a/.github/workflows/triage-unlabelled.yml +++ /dev/null @@ -1,54 +0,0 @@ -name: Move unlabelled from needs info columns to triaged - -on: - issues: - types: [unlabeled] -permissions: {} -jobs: - move_no_longer_needs_info_issues: - name: Move no longer X-Needs-Info issues to Triaged - runs-on: ubuntu-24.04 - if: > - !contains(github.event.issue.labels.*.name, 'X-Needs-Info') - steps: - - id: set_fields - uses: nipe0324/update-project-v2-item-field@c4af58452d1c5a788c1ea4f20e073fa722ec4a6b #v2.0.2 - with: - project-url: ${{ env.PROJECT_URL }} - github-token: ${{ secrets.ELEMENT_BOT_TOKEN }} - skip-update-script: | - const isIssue = item.type === 'ISSUE' - const status = item.fieldValues['Status'] - return !isIssue || status !== 'Needs info' - field-name: Status - field-value: "Triaged" - env: - PROJECT_URL: https://github.com/orgs/element-hq/projects/120 - - remove_Z-Labs_label: - name: Remove Z-Labs label when features behind labs flags are removed - runs-on: ubuntu-24.04 - if: > - !(contains(github.event.issue.labels.*.name, 'A-Maths') || - contains(github.event.issue.labels.*.name, 'A-Message-Pinning') || - contains(github.event.issue.labels.*.name, 'A-Location-Sharing') || - contains(github.event.issue.labels.*.name, 'Z-IA') || - contains(github.event.issue.labels.*.name, 'A-Jump-To-Date') || - contains(github.event.issue.labels.*.name, 'A-Themes-Custom') || - contains(github.event.issue.labels.*.name, 'A-E2EE-Dehydration') || - contains(github.event.issue.labels.*.name, 'A-Tags') || - contains(github.event.issue.labels.*.name, 'A-Video-Rooms') || - contains(github.event.issue.labels.*.name, 'A-Message-Starring') || - contains(github.event.issue.labels.*.name, 'A-Rich-Text-Editor') || - contains(github.event.issue.labels.*.name, 'A-Element-Call')) && - contains(github.event.issue.labels.*.name, 'Z-Labs') - steps: - - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9 - with: - script: | - github.rest.issues.removeLabel({ - issue_number: context.issue.number, - owner: context.repo.owner, - repo: context.repo.repo, - name: ['Z-Labs'] - }) diff --git a/.github/workflows/update-jitsi.yml b/.github/workflows/update-jitsi.yml deleted file mode 100644 index 7d56d6d41..000000000 --- a/.github/workflows/update-jitsi.yml +++ /dev/null @@ -1,37 +0,0 @@ -# Re-fetches the Jitsi SDK and opens a PR to update it if it's different from what's in the repository -name: Update Jitsi -on: - workflow_dispatch: {} - schedule: - - cron: "0 3 * * 0" # 3am every Sunday -permissions: {} # We use ELEMENT_BOT_TOKEN instead -jobs: - update: - runs-on: ubuntu-24.04 - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - with: - persist-credentials: false - - - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 - - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 - with: - cache: "pnpm" - node-version: "lts/*" - - - name: Install Deps - run: "pnpm install --frozen-lockfile" - - - name: Fetch Jitsi - working-directory: apps/web - run: "pnpm vendor:jitsi" - - - name: Create Pull Request - uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8 - with: - token: ${{ secrets.ELEMENT_BOT_TOKEN }} - branch: actions/jitsi-update - delete-branch: true - title: Jitsi Update - labels: | - T-Task diff --git a/.github/workflows/update-topics.yaml b/.github/workflows/update-topics.yaml deleted file mode 100644 index 698c8da80..000000000 --- a/.github/workflows/update-topics.yaml +++ /dev/null @@ -1,119 +0,0 @@ -name: Update release topics -on: - workflow_dispatch: - inputs: - expected_status: - description: What type of release is the next expected release - required: true - default: RC - type: choice - options: - - RC - - Release - expected_date: - description: Expected release date e.g. July 11th - required: true - type: string -concurrency: ${{ github.workflow }} -permissions: {} # No permissions required -jobs: - bot: - name: Release topic update - runs-on: ubuntu-24.04 - environment: Matrix - steps: - - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9 - env: - HS_URL: ${{ secrets.BETABOT_HS_URL }} - LOBBY_ROOM_ID: ${{ secrets.ROOM_ID }} - PUBLIC_DISCUSSION_ROOM_ID: "!xUW4PpAe1CmThA3r2wI8IrgwwsK006-zqWdJCljpd10" - ANNOUNCEMENT_ROOM_ID: "!ars5ndgI6IIYZXECiJ-u8YljHNzShJn3nHdB-3rYI2M" - TOKEN: ${{ secrets.BETABOT_ACCESS_TOKEN }} - RELEASE_STATUS: "Release status: ${{ inputs.expected_status }} expected ${{ inputs.expected_date }}" - with: - script: | - const { HS_URL, TOKEN, RELEASE_STATUS, LOBBY_ROOM_ID, PUBLIC_DISCUSSION_ROOM_ID, ANNOUNCEMENT_ROOM_ID } = process.env; - - const repo = context.repo; - const { data } = await github.rest.repos.getLatestRelease({ - owner: repo.owner, - repo: repo.repo, - }); - console.log("Found latest version: " + data.tag_name); - - const releaseTopic = `Stable: ${data.tag_name} | ${RELEASE_STATUS}`; - console.log("Release topic: " + releaseTopic); - - const regex = /Stable: v(.+) \| Release status: (\w+) expected (\w+ \d+\w\w)/gm; - - async function updateReleaseInTopic(roomId) { - const apiUrl = `${HS_URL}/_matrix/client/v3/rooms/${roomId}/state/m.room.topic/`; - const headers = { - "Content-Type": "application/json", - "Authorization": `Bearer ${TOKEN}`, - }; - await fetch(`${HS_URL}/_matrix/client/v3/rooms/${roomId}/join`, { - method: "POST", - headers, - body: "{}", - }); - - let res = await fetch(apiUrl, { - method: "GET", - headers, - }); - - if (!res.ok) { - console.log(roomId, "failed to fetch", await res.text()); - return; - } - - const data = await res.json(); - console.log(roomId, "got event", data); - - if (!regex.test(data.topic)) { - core.setFailed("Topic format is incorrect for room " + roomId); - return; - } - - const topic = data.topic.replace(regex, releaseTopic); - if (topic === data.topic) { - console.log(roomId, "nothing to do"); - return; - } - if (data["org.matrix.msc3765.topic"]) { - data["org.matrix.msc3765.topic"]?.["m.text"].forEach(d => { - d.body = d.body.replace(regex, releaseTopic); - }); - } - if (data["m.topic"]) { - data["m.topic"]?.["m.text"].forEach(d => { - d.body = d.body.replace(regex, releaseTopic); - }); - } - - res = await fetch(apiUrl, { - method: "PUT", - body: JSON.stringify({ - ...data, - topic, - }), - headers, - }); - - if (res.ok) { - const resJson = res.json(); - if (resJson.errcode) { - core.setFailed(`Error updating ${roomId}: ${resJson.error}`); - } else { - console.log(roomId, "topic updated:", topic); - } - } else { - const errText = await res.text(); - core.setFailed(`Error updating ${roomId}: ${errText}`); - } - } - - await updateReleaseInTopic(LOBBY_ROOM_ID); - await updateReleaseInTopic(PUBLIC_DISCUSSION_ROOM_ID); - await updateReleaseInTopic(ANNOUNCEMENT_ROOM_ID);