ci: reduce workflows to fork-relevant CI, fix upstream checkouts (Issue #2)
Removed ~37 workflow files that are unmodified upstream tooling this fork doesn't use (Netlify, SonarCloud, Localazy, release-drafter/backport, GitHub issue-triage bots, npm-publish, Cloudflare Pages deploy, Docker push to ghcr.io/element-hq). Enabling Actions for this repo would have activated all of them simultaneously against a single-capacity shared runner - most would just fail loudly and starve the one job slot shared with other repos. Kept build-and-test.yaml (the actual comprehensive build+test+desktop workflow) and its build_desktop_*.yaml sub-workflows. Fixed: push trigger now targets `main` (was `staging`/`master`, neither of which exist here - push events never fired at all before), 4 checkout steps now check out this fork instead of element-hq/element-web, and removed the macOS desktop build job since the registered runner (builder-1) has no macOS label and would queue forever instead of failing cleanly. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
45fb329577
commit
77ffeb4514
@@ -1,34 +0,0 @@
|
|||||||
name: Backport
|
|
||||||
on:
|
|
||||||
# Privilege escalation necessary to enable backporting PRs from forks
|
|
||||||
# 🚨 We must not execute any checked out code here.
|
|
||||||
pull_request_target: # zizmor: ignore[dangerous-triggers]
|
|
||||||
types:
|
|
||||||
- closed
|
|
||||||
- labeled
|
|
||||||
branches:
|
|
||||||
- develop
|
|
||||||
|
|
||||||
permissions: {} # We use ELEMENT_BOT_TOKEN instead
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
backport:
|
|
||||||
name: Backport
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
# Only react to merged PRs for security reasons.
|
|
||||||
# See https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target.
|
|
||||||
if: >
|
|
||||||
github.event.pull_request.merged
|
|
||||||
&& (
|
|
||||||
github.event.action == 'closed'
|
|
||||||
|| (
|
|
||||||
github.event.action == 'labeled'
|
|
||||||
&& contains(github.event.label.name, 'backport')
|
|
||||||
)
|
|
||||||
)
|
|
||||||
steps:
|
|
||||||
- uses: tibdex/backport@9565281eda0731b1d20c4025c43339fb0a23812e # v2
|
|
||||||
with:
|
|
||||||
labels_template: "<%= JSON.stringify([...labels, 'X-Release-Blocker']) %>"
|
|
||||||
# We can't use GITHUB_TOKEN here or CI won't run on the new PR
|
|
||||||
github_token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
@@ -1,48 +0,0 @@
|
|||||||
# Triggers after the playwright tests have finished,
|
|
||||||
# taking the artifact and uploading it to Netlify for easier viewing
|
|
||||||
name: Upload End to End Test report to Netlify
|
|
||||||
on:
|
|
||||||
# Privilege escalation necessary to publish to Netlify
|
|
||||||
# 🚨 We must not execute any checked out code here.
|
|
||||||
workflow_run: # zizmor: ignore[dangerous-triggers]
|
|
||||||
workflows: ["Build & Test"]
|
|
||||||
types:
|
|
||||||
- completed
|
|
||||||
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.workflow }}-${{ github.event.workflow_run.head_branch || github.run_id }}
|
|
||||||
cancel-in-progress: ${{ github.event.workflow_run.event == 'pull_request' }}
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
report:
|
|
||||||
if: github.event.workflow_run.conclusion != 'cancelled'
|
|
||||||
name: Report results
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
environment: Netlify
|
|
||||||
permissions:
|
|
||||||
statuses: write
|
|
||||||
deployments: write
|
|
||||||
actions: read
|
|
||||||
steps:
|
|
||||||
- name: Download HTML report
|
|
||||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
||||||
with:
|
|
||||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
run-id: ${{ github.event.workflow_run.id }}
|
|
||||||
name: html-report
|
|
||||||
path: playwright-report
|
|
||||||
|
|
||||||
- name: 📤 Deploy to Netlify
|
|
||||||
uses: matrix-org/netlify-pr-preview@9805cd123fc9a7e421e35340a05e1ebc5dee46b5 # v3
|
|
||||||
with:
|
|
||||||
path: playwright-report
|
|
||||||
owner: ${{ github.event.workflow_run.head_repository.owner.login }}
|
|
||||||
branch: ${{ github.event.workflow_run.head_branch }}
|
|
||||||
revision: ${{ github.event.workflow_run.head_sha }}
|
|
||||||
token: ${{ secrets.NETLIFY_AUTH_TOKEN }}
|
|
||||||
site_id: ${{ vars.NETLIFY_SITE_ID }}
|
|
||||||
desc: Playwright Report
|
|
||||||
deployment_env: EndToEndTests
|
|
||||||
prefix: "e2e-"
|
|
||||||
@@ -16,8 +16,7 @@ on:
|
|||||||
merge_group:
|
merge_group:
|
||||||
types: [checks_requested]
|
types: [checks_requested]
|
||||||
push:
|
push:
|
||||||
# We do not build on push to develop as the merge_group check handles that
|
branches: [main]
|
||||||
branches: [staging, master]
|
|
||||||
|
|
||||||
# support triggering from other workflows
|
# support triggering from other workflows
|
||||||
workflow_call:
|
workflow_call:
|
||||||
@@ -60,7 +59,7 @@ jobs:
|
|||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
||||||
with:
|
with:
|
||||||
repository: element-hq/element-web
|
repository: ${{ github.repository }}
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
||||||
@@ -137,7 +136,7 @@ jobs:
|
|||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
||||||
with:
|
with:
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
repository: element-hq/element-web
|
repository: ${{ github.repository }}
|
||||||
|
|
||||||
- name: 📥 Download artifact
|
- name: 📥 Download artifact
|
||||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
||||||
@@ -237,15 +236,8 @@ jobs:
|
|||||||
arch: ${{ matrix.arch }}
|
arch: ${{ matrix.arch }}
|
||||||
blob_report: true
|
blob_report: true
|
||||||
|
|
||||||
build_ed_macos:
|
# build_ed_macos entfernt: der einzige Gitea-Actions-Runner (builder-1, CFGMON) hat
|
||||||
needs: prepare_ed
|
# kein macOS-Label - der Job wuerde nie einen Runner finden statt sauber zu scheitern.
|
||||||
name: "Desktop macOS"
|
|
||||||
uses: ./.github/workflows/build_desktop_macos.yaml
|
|
||||||
# Skip macOS builds on PRs, as the Linux amd64 build is enough of a smoke test and includes the screenshot tests
|
|
||||||
# and we have a very low limit of concurrent macos runners (5) across the Github org.
|
|
||||||
if: github.event_name != 'pull_request' || contains(github.event.pull_request.labels.*.name, 'X-Run-All-Tests')
|
|
||||||
with:
|
|
||||||
blob_report: true
|
|
||||||
|
|
||||||
complete:
|
complete:
|
||||||
name: end-to-end-tests
|
name: end-to-end-tests
|
||||||
@@ -256,7 +248,6 @@ jobs:
|
|||||||
- prepare_ed
|
- prepare_ed
|
||||||
- build_ed_windows
|
- build_ed_windows
|
||||||
- build_ed_linux
|
- build_ed_linux
|
||||||
- build_ed_macos
|
|
||||||
if: always()
|
if: always()
|
||||||
runs-on: ubuntu-24.04
|
runs-on: ubuntu-24.04
|
||||||
steps:
|
steps:
|
||||||
@@ -264,7 +255,7 @@ jobs:
|
|||||||
if: needs.build_ew.outputs.skip == 'false'
|
if: needs.build_ew.outputs.skip == 'false'
|
||||||
with:
|
with:
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
repository: element-hq/element-web
|
repository: ${{ github.repository }}
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
||||||
if: needs.build_ew.outputs.skip == 'false'
|
if: needs.build_ew.outputs.skip == 'false'
|
||||||
|
|||||||
@@ -1,76 +0,0 @@
|
|||||||
name: Build
|
|
||||||
on:
|
|
||||||
pull_request: {}
|
|
||||||
push:
|
|
||||||
branches: [develop, master]
|
|
||||||
merge_group:
|
|
||||||
types: [checks_requested]
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.workflow }}-${{ github.head_ref || github.sha }}
|
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
|
||||||
# develop pushes and repository_dispatch handled in build_develop.yaml
|
|
||||||
env:
|
|
||||||
# This must be set for fetchdep.sh to get the right branch
|
|
||||||
PR_NUMBER: ${{ github.event.pull_request.number }}
|
|
||||||
NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes
|
|
||||||
permissions: {} # No permissions required
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
name: "Build on ${{ matrix.image }}"
|
|
||||||
# We build on all 3 platforms to ensure we don't have any OS-specific build incompatibilities
|
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
matrix:
|
|
||||||
image:
|
|
||||||
- ubuntu-24.04
|
|
||||||
- windows-2022
|
|
||||||
- macos-14
|
|
||||||
isDevelop:
|
|
||||||
- ${{ github.event_name == 'push' && github.ref_name == 'develop' }}
|
|
||||||
isPullRequest:
|
|
||||||
- ${{ github.event_name == 'pull_request' }}
|
|
||||||
# Skip the ubuntu-24.04 build for the develop branch as the dedicated CD build_develop workflow handles that
|
|
||||||
# Skip the non-linux builds for pull requests as Windows is awfully slow, so run in merge queue only
|
|
||||||
exclude:
|
|
||||||
- isDevelop: true
|
|
||||||
image: ubuntu-24.04
|
|
||||||
- isPullRequest: true
|
|
||||||
image: windows-2022
|
|
||||||
- isPullRequest: true
|
|
||||||
image: macos-14
|
|
||||||
runs-on: ${{ matrix.image }}
|
|
||||||
defaults:
|
|
||||||
run:
|
|
||||||
shell: bash
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
# Disable cache on Windows as it is slower than not caching
|
|
||||||
# https://github.com/actions/setup-node/issues/975
|
|
||||||
cache: ${{ runner.os != 'Windows' && 'pnpm' || '' }}
|
|
||||||
node-version: "lts/*"
|
|
||||||
|
|
||||||
- name: Fetch layered build
|
|
||||||
run: ./scripts/layered.sh
|
|
||||||
|
|
||||||
- name: Copy config
|
|
||||||
working-directory: apps/web
|
|
||||||
run: cp element.io/develop/config.json config.json
|
|
||||||
|
|
||||||
- name: Build
|
|
||||||
working-directory: apps/web
|
|
||||||
env:
|
|
||||||
CI_PACKAGE: true
|
|
||||||
run: VERSION=$(scripts/get-version-from-git.sh) pnpm run build
|
|
||||||
|
|
||||||
- name: Upload Artifact
|
|
||||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
||||||
with:
|
|
||||||
name: webapp-${{ matrix.image }}
|
|
||||||
path: apps/web/webapp
|
|
||||||
retention-days: 1
|
|
||||||
@@ -1,86 +0,0 @@
|
|||||||
name: Build Debian package
|
|
||||||
on:
|
|
||||||
release:
|
|
||||||
types: [published]
|
|
||||||
concurrency: ${{ github.workflow }}
|
|
||||||
permissions: {} # We use ELEMENT_BOT_TOKEN instead
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
name: Build package
|
|
||||||
environment: packages.element.io
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
env:
|
|
||||||
R2_INCOMING_BUCKET: ${{ vars.R2_INCOMING_BUCKET }}
|
|
||||||
R2_URL: ${{ vars.CF_R2_S3_API }}
|
|
||||||
VERSION: ${{ github.ref_name }}
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- name: Download package
|
|
||||||
working-directory: apps/web
|
|
||||||
run: |
|
|
||||||
wget "https://github.com/element-hq/element-web/releases/download/$VERSION/element-$VERSION.tar.gz"
|
|
||||||
wget "https://github.com/element-hq/element-web/releases/download/$VERSION/element-$VERSION.tar.gz.asc"
|
|
||||||
|
|
||||||
- name: Check GPG signature
|
|
||||||
working-directory: apps/web
|
|
||||||
run: |
|
|
||||||
wget "https://packages.element.io/element-release-key.gpg"
|
|
||||||
gpg --import element-release-key.gpg
|
|
||||||
gpg --fingerprint "$FINGERPRINT"
|
|
||||||
gpg --verify "element-$VERSION.tar.gz.asc" "element-$VERSION.tar.gz"
|
|
||||||
env:
|
|
||||||
FINGERPRINT: ${{ vars.GPG_FINGERPRINT }}
|
|
||||||
|
|
||||||
- name: Prepare
|
|
||||||
working-directory: apps/web
|
|
||||||
run: |
|
|
||||||
mkdir -p debian/tmp/DEBIAN
|
|
||||||
find debian -maxdepth 1 -type f -exec cp "{}" debian/tmp/DEBIAN/ \;
|
|
||||||
mkdir -p debian/tmp/usr/share/element-web/ debian/tmp/etc/element-web/
|
|
||||||
|
|
||||||
tar -xf "element-$VERSION.tar.gz" -C debian/tmp/usr/share/element-web --strip-components=1 --no-same-owner --no-same-permissions
|
|
||||||
mv debian/tmp/usr/share/element-web/config.sample.json debian/tmp/etc/element-web/config.json
|
|
||||||
ln -s /etc/element-web/config.json debian/tmp/usr/share/element-web/config.json
|
|
||||||
|
|
||||||
- name: Write changelog
|
|
||||||
working-directory: apps/web
|
|
||||||
run: |
|
|
||||||
VERSION=$(cat package.json | jq -r .version)
|
|
||||||
TIME=$(date -d "$PUBLISHED_AT" -R)
|
|
||||||
{
|
|
||||||
echo "element-web ($VERSION) default; urgency=medium"
|
|
||||||
echo "$BODY" | sed 's/^##/\n */g;s/^\*/ */g' | perl -pe 's/\[.+?]\((.+?)\)/\1/g'
|
|
||||||
echo ""
|
|
||||||
echo " -- $ACTOR <support@element.io> $TIME"
|
|
||||||
} > debian/tmp/DEBIAN/changelog
|
|
||||||
env:
|
|
||||||
ACTOR: ${{ github.actor }}
|
|
||||||
VERSION: ${{ github.event.release.tag_name }}
|
|
||||||
BODY: ${{ github.event.release.body }}
|
|
||||||
PUBLISHED_AT: ${{ github.event.release.published_at }}
|
|
||||||
|
|
||||||
- name: Build deb package
|
|
||||||
working-directory: apps/web
|
|
||||||
run: |
|
|
||||||
VERSION=$(cat package.json | jq -r .version)
|
|
||||||
dpkg-gencontrol -v"$VERSION" -ldebian/tmp/DEBIAN/changelog
|
|
||||||
dpkg-deb -Zxz --root-owner-group --build debian/tmp element-web.deb
|
|
||||||
|
|
||||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
||||||
with:
|
|
||||||
name: element-web.deb
|
|
||||||
path: apps/web/element-web.deb
|
|
||||||
retention-days: 14
|
|
||||||
|
|
||||||
- name: Publish to packages.element.io
|
|
||||||
if: github.event.release.prerelease == false
|
|
||||||
uses: element-hq/packages.element.io@master # zizmor: ignore[unpinned-uses]
|
|
||||||
with:
|
|
||||||
file: apps/web/element-web.deb
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
bucket-api: ${{ vars.CF_R2_S3_API }}
|
|
||||||
bucket-key-id: ${{ secrets.CF_R2_ACCESS_KEY_ID }}
|
|
||||||
bucket-access-key: ${{ secrets.CF_R2_TOKEN }}
|
|
||||||
@@ -1,313 +0,0 @@
|
|||||||
name: Build and Deploy
|
|
||||||
on:
|
|
||||||
# Nightly build
|
|
||||||
schedule:
|
|
||||||
- cron: "0 9 * * *"
|
|
||||||
# Release build
|
|
||||||
release:
|
|
||||||
types: [published]
|
|
||||||
# Manual nightly & release
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
mode:
|
|
||||||
description: What type of build to trigger. Release builds MUST be ran from the `master` branch.
|
|
||||||
required: true
|
|
||||||
default: nightly
|
|
||||||
type: choice
|
|
||||||
options:
|
|
||||||
- nightly
|
|
||||||
- release
|
|
||||||
macos:
|
|
||||||
description: Build macOS
|
|
||||||
required: true
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
windows:
|
|
||||||
description: Build Windows
|
|
||||||
required: true
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
linux:
|
|
||||||
description: Build Linux
|
|
||||||
required: true
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
deploy:
|
|
||||||
description: Deploy artifacts
|
|
||||||
required: true
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
run-name: Element ${{ inputs.mode != 'release' && github.event_name != 'release' && 'Nightly' || 'Desktop' }}
|
|
||||||
concurrency: ${{ github.workflow }}
|
|
||||||
env:
|
|
||||||
R2_BUCKET: ${{ vars.R2_BUCKET }}
|
|
||||||
permissions: {} # Uses ELEMENT_BOT_TOKEN
|
|
||||||
jobs:
|
|
||||||
prepare:
|
|
||||||
uses: ./.github/workflows/build_desktop_prepare.yaml
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
with:
|
|
||||||
config: element.io/${{ inputs.mode || (github.event_name == 'release' && 'release') || 'nightly' }}
|
|
||||||
version: ${{ (inputs.mode != 'release' && github.event_name != 'release') && 'develop' || '' }}
|
|
||||||
nightly: ${{ inputs.mode != 'release' && github.event_name != 'release' }}
|
|
||||||
deploy: ${{ inputs.deploy || (github.event_name != 'workflow_dispatch' && github.event.release.prerelease != true) }}
|
|
||||||
secrets:
|
|
||||||
CF_R2_ACCESS_KEY_ID: ${{ secrets.CF_R2_ACCESS_KEY_ID }}
|
|
||||||
CF_R2_TOKEN: ${{ secrets.CF_R2_TOKEN }}
|
|
||||||
|
|
||||||
trigger-pro-pipeline:
|
|
||||||
name: Trigger Pro pipeline
|
|
||||||
needs: prepare
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4
|
|
||||||
with:
|
|
||||||
repository: element-hq/element-web-pro
|
|
||||||
token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
event-type: trigger-pipeline
|
|
||||||
client-payload: |-
|
|
||||||
{
|
|
||||||
"base-ref": "${{ github.ref_name }}"
|
|
||||||
}
|
|
||||||
|
|
||||||
windows:
|
|
||||||
if: github.event_name != 'workflow_dispatch' || inputs.windows
|
|
||||||
needs: prepare
|
|
||||||
name: Windows ${{ matrix.arch }}
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
arch: [x64, arm64]
|
|
||||||
uses: ./.github/workflows/build_desktop_windows.yaml
|
|
||||||
secrets: inherit # zizmor: ignore[secrets-inherit]
|
|
||||||
with:
|
|
||||||
sign: true
|
|
||||||
arch: ${{ matrix.arch }}
|
|
||||||
version: ${{ needs.prepare.outputs.nightly-version }}
|
|
||||||
|
|
||||||
macos:
|
|
||||||
if: github.event_name != 'workflow_dispatch' || inputs.macos
|
|
||||||
needs: prepare
|
|
||||||
name: macOS
|
|
||||||
uses: ./.github/workflows/build_desktop_macos.yaml
|
|
||||||
secrets: inherit # zizmor: ignore[secrets-inherit]
|
|
||||||
with:
|
|
||||||
sign: true
|
|
||||||
base-url: https://packages.element.io/${{ needs.prepare.outputs.packages-dir }}
|
|
||||||
version: ${{ needs.prepare.outputs.nightly-version }}
|
|
||||||
|
|
||||||
linux:
|
|
||||||
if: github.event_name != 'workflow_dispatch' || inputs.linux
|
|
||||||
needs: prepare
|
|
||||||
name: Linux ${{ matrix.arch }} (sqlcipher ${{ matrix.sqlcipher }})
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
arch: [amd64, arm64]
|
|
||||||
sqlcipher: [static]
|
|
||||||
uses: ./.github/workflows/build_desktop_linux.yaml
|
|
||||||
with:
|
|
||||||
arch: ${{ matrix.arch }}
|
|
||||||
sqlcipher: ${{ matrix.sqlcipher }}
|
|
||||||
version: ${{ needs.prepare.outputs.nightly-version }}
|
|
||||||
|
|
||||||
deploy:
|
|
||||||
needs:
|
|
||||||
- prepare
|
|
||||||
- macos
|
|
||||||
- linux
|
|
||||||
- windows
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
name: ${{ needs.prepare.outputs.deploy == 'true' && 'Deploy' || 'Deploy (dry-run)' }}
|
|
||||||
if: always() && !contains(needs.*.result, 'failure') && !contains(needs.*.result, 'cancelled')
|
|
||||||
environment: ${{ needs.prepare.outputs.deploy == 'true' && 'packages.element.io' || '' }}
|
|
||||||
steps:
|
|
||||||
- name: Download artifacts
|
|
||||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
||||||
|
|
||||||
- name: Prepare artifacts for deployment
|
|
||||||
run: |
|
|
||||||
set -ex
|
|
||||||
|
|
||||||
# Windows
|
|
||||||
for arch in x64 arm64
|
|
||||||
do
|
|
||||||
if [ -d "win-$arch" ]; then
|
|
||||||
mkdir -p packages.element.io/{install,update}/win32/$arch
|
|
||||||
mv win-$arch/squirrel-windows*/*.exe "packages.element.io/install/win32/$arch/"
|
|
||||||
mv win-$arch/squirrel-windows*/*.nupkg "packages.element.io/update/win32/$arch/"
|
|
||||||
mv win-$arch/squirrel-windows*/RELEASES "packages.element.io/update/win32/$arch/"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
|
|
||||||
# macOS
|
|
||||||
if [ -d macos ]; then
|
|
||||||
mkdir -p packages.element.io/{install,update}/macos
|
|
||||||
mv macos/*.dmg packages.element.io/install/macos/
|
|
||||||
mv macos/*-mac.zip packages.element.io/update/macos/
|
|
||||||
mv macos/*.json packages.element.io/update/macos/
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Linux
|
|
||||||
if [ -d linux-amd64-sqlcipher-static ]; then
|
|
||||||
mkdir -p packages.element.io/install/linux/glibc-x86-64
|
|
||||||
mv linux-amd64-sqlcipher-static/*.tar.gz packages.element.io/install/linux/glibc-x86-64
|
|
||||||
fi
|
|
||||||
if [ -d linux-arm64-sqlcipher-static ]; then
|
|
||||||
mkdir -p packages.element.io/install/linux/glibc-aarch64
|
|
||||||
mv linux-arm64-sqlcipher-static/*.tar.gz packages.element.io/install/linux/glibc-aarch64
|
|
||||||
fi
|
|
||||||
|
|
||||||
# We don't wish to store the installer for every nightly ever, so we only keep the latest
|
|
||||||
- name: "[Nightly] Strip version from installer file"
|
|
||||||
if: needs.prepare.outputs.nightly-version != ''
|
|
||||||
run: |
|
|
||||||
set -ex
|
|
||||||
|
|
||||||
# Windows
|
|
||||||
for arch in x64 arm64
|
|
||||||
do
|
|
||||||
if [ -d "win-$arch" ]; then mv packages.element.io/install/win32/$arch/{*,"Element Nightly Setup"}.exe; fi
|
|
||||||
done
|
|
||||||
|
|
||||||
# macOS
|
|
||||||
if [ -d macos ]; then mv packages.element.io/install/macos/{*,"Element Nightly"}.dmg; fi
|
|
||||||
|
|
||||||
# Linux
|
|
||||||
if [ -d linux-amd64-sqlcipher-static ]; then mv packages.element.io/install/linux/glibc-x86-64/{*,element-desktop-nightly}.tar.gz; fi
|
|
||||||
if [ -d linux-arm64-sqlcipher-static ]; then mv packages.element.io/install/linux/glibc-aarch64/{*,element-desktop-nightly}.tar.gz; fi
|
|
||||||
|
|
||||||
- name: "[Release] Prepare release latest symlink"
|
|
||||||
if: needs.prepare.outputs.nightly-version == ''
|
|
||||||
run: |
|
|
||||||
set -ex
|
|
||||||
|
|
||||||
# Windows
|
|
||||||
for arch in x64 arm64
|
|
||||||
do
|
|
||||||
if [ -d "win-$arch" ]; then
|
|
||||||
pushd packages.element.io/install/win32/$arch
|
|
||||||
ln -s "$(find . -type f -iname "*.exe" | xargs -0 -n1 -- basename)" "Element Setup.exe"
|
|
||||||
popd
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
|
|
||||||
# macOS
|
|
||||||
if [ -d macos ]; then
|
|
||||||
pushd packages.element.io/install/macos
|
|
||||||
ln -s "$(find . -type f -iname "*.dmg" | xargs -0 -n1 -- basename)" "Element.dmg"
|
|
||||||
popd
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Linux
|
|
||||||
if [ -d linux-amd64-sqlcipher-static ]; then
|
|
||||||
pushd packages.element.io/install/linux/glibc-x86-64
|
|
||||||
ln -s "$(find . -type f -iname "*.tar.gz" | xargs -0 -n1 -- basename)" "element-desktop.tar.gz"
|
|
||||||
popd
|
|
||||||
fi
|
|
||||||
if [ -d linux-arm64-sqlcipher-static ]; then
|
|
||||||
pushd packages.element.io/install/linux/glibc-aarch64
|
|
||||||
ln -s "$(find . -type f -iname "*.tar.gz" | xargs -0 -n1 -- basename)" "element-desktop.tar.gz"
|
|
||||||
popd
|
|
||||||
fi
|
|
||||||
|
|
||||||
- name: Stash packages.element.io
|
|
||||||
if: needs.prepare.outputs.deploy == 'false'
|
|
||||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
||||||
with:
|
|
||||||
name: packages.element.io
|
|
||||||
path: packages.element.io
|
|
||||||
|
|
||||||
# Checksum algorithm specified as per https://developers.cloudflare.com/r2/examples/aws/aws-cli/
|
|
||||||
- name: Deploy artifacts
|
|
||||||
if: needs.prepare.outputs.deploy == 'true'
|
|
||||||
run: |
|
|
||||||
set -x
|
|
||||||
aws s3 cp --recursive packages.element.io/ s3://$R2_BUCKET/$DEPLOYMENT_DIR --endpoint-url $R2_URL --region auto --checksum-algorithm CRC32
|
|
||||||
env:
|
|
||||||
AWS_ACCESS_KEY_ID: ${{ secrets.CF_R2_ACCESS_KEY_ID }}
|
|
||||||
AWS_SECRET_ACCESS_KEY: ${{ secrets.CF_R2_TOKEN }}
|
|
||||||
R2_URL: ${{ vars.CF_R2_S3_API }}
|
|
||||||
DEPLOYMENT_DIR: ${{ needs.prepare.outputs.packages-dir }}
|
|
||||||
|
|
||||||
- name: Notify packages.element.io of new files
|
|
||||||
if: needs.prepare.outputs.deploy == 'true'
|
|
||||||
uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4
|
|
||||||
with:
|
|
||||||
token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
repository: element-hq/packages.element.io
|
|
||||||
event-type: packages-index
|
|
||||||
|
|
||||||
- name: Find debs
|
|
||||||
id: deb
|
|
||||||
if: needs.linux.result == 'success'
|
|
||||||
run: |
|
|
||||||
set -x
|
|
||||||
|
|
||||||
for arch in amd64 arm64
|
|
||||||
do
|
|
||||||
echo "$arch=$(ls linux-$arch-sqlcipher-static/*.deb | tail -n1)" >> $GITHUB_OUTPUT
|
|
||||||
done
|
|
||||||
|
|
||||||
- name: Stash debs
|
|
||||||
if: needs.prepare.outputs.deploy == 'false' && needs.linux.result == 'success'
|
|
||||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
||||||
with:
|
|
||||||
name: debs
|
|
||||||
path: |
|
|
||||||
${{ steps.deb.outputs.amd64 }}
|
|
||||||
${{ steps.deb.outputs.arm64 }}
|
|
||||||
|
|
||||||
- name: Publish amd64 deb to packages.element.io
|
|
||||||
uses: element-hq/packages.element.io@master # zizmor: ignore[unpinned-uses]
|
|
||||||
if: needs.prepare.outputs.deploy == 'true' && needs.linux.result == 'success'
|
|
||||||
with:
|
|
||||||
file: ${{ steps.deb.outputs.amd64 }}
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
bucket-api: ${{ vars.CF_R2_S3_API }}
|
|
||||||
bucket-key-id: ${{ secrets.CF_R2_ACCESS_KEY_ID }}
|
|
||||||
bucket-access-key: ${{ secrets.CF_R2_TOKEN }}
|
|
||||||
|
|
||||||
- name: Publish arm64 deb to packages.element.io
|
|
||||||
uses: element-hq/packages.element.io@master # zizmor: ignore[unpinned-uses]
|
|
||||||
if: needs.prepare.outputs.deploy == 'true' && needs.linux.result == 'success'
|
|
||||||
with:
|
|
||||||
file: ${{ steps.deb.outputs.arm64 }}
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
bucket-api: ${{ vars.CF_R2_S3_API }}
|
|
||||||
bucket-key-id: ${{ secrets.CF_R2_ACCESS_KEY_ID }}
|
|
||||||
bucket-access-key: ${{ secrets.CF_R2_TOKEN }}
|
|
||||||
|
|
||||||
deploy-ess:
|
|
||||||
needs: deploy
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
name: Deploy builds to ESS
|
|
||||||
if: needs.prepare.outputs.deploy == 'true' && github.event_name == 'release'
|
|
||||||
env:
|
|
||||||
BUCKET_NAME: "element-desktop-msi.onprem.element.io"
|
|
||||||
AWS_REGION: "eu-central-1"
|
|
||||||
permissions:
|
|
||||||
id-token: write # This is required for requesting the JWT
|
|
||||||
steps:
|
|
||||||
- name: Configure AWS credentials
|
|
||||||
uses: aws-actions/configure-aws-credentials@d979d5b3a71173a29b74b5b88418bfda9437d885 # v6
|
|
||||||
with:
|
|
||||||
role-to-assume: arn:aws:iam::264135176173:role/Push-ElementDesktop-MSI
|
|
||||||
role-session-name: githubaction-run-${{ github.run_id }}
|
|
||||||
aws-region: ${{ env.AWS_REGION }}
|
|
||||||
|
|
||||||
- name: Download artifacts
|
|
||||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
||||||
with:
|
|
||||||
pattern: win-*
|
|
||||||
|
|
||||||
- name: Copy files to S3
|
|
||||||
run: |
|
|
||||||
set -x
|
|
||||||
|
|
||||||
PREFIX="${VERSION%.*}"
|
|
||||||
for file in win-*/*.msi; do
|
|
||||||
filename=$(basename "$file")
|
|
||||||
aws s3 cp "$file" "s3://${{ env.BUCKET_NAME }}/$PREFIX/$filename"
|
|
||||||
done
|
|
||||||
env:
|
|
||||||
VERSION: ${{ github.event.release.tag_name }}
|
|
||||||
@@ -56,7 +56,7 @@ jobs:
|
|||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
||||||
with:
|
with:
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
repository: element-hq/element-web
|
repository: ${{ github.repository }}
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
||||||
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
||||||
|
|||||||
@@ -1,141 +0,0 @@
|
|||||||
# Separate to the main build workflow for access to develop
|
|
||||||
# environment secrets, largely similar to build.yaml.
|
|
||||||
name: Build and Deploy develop
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches: [develop]
|
|
||||||
repository_dispatch:
|
|
||||||
types: [element-web-notify]
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.repository_owner }}-${{ github.workflow }}-${{ github.ref_name }}
|
|
||||||
cancel-in-progress: true
|
|
||||||
env:
|
|
||||||
NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes
|
|
||||||
permissions: {}
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
name: "Build & Deploy develop.element.io"
|
|
||||||
# Only respect triggers from our develop branch, ignore that of forks
|
|
||||||
if: github.repository == 'element-hq/element-web'
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
environment: develop
|
|
||||||
permissions:
|
|
||||||
checks: read
|
|
||||||
pages: write
|
|
||||||
deployments: write
|
|
||||||
env:
|
|
||||||
R2_BUCKET: "element-web-develop"
|
|
||||||
R2_URL: ${{ vars.CF_R2_S3_API }}
|
|
||||||
R2_PUBLIC_URL: "https://element-web-develop.element.io"
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
cache: "pnpm"
|
|
||||||
node-version: "lts/*"
|
|
||||||
|
|
||||||
- name: Install Dependencies
|
|
||||||
run: "./scripts/layered.sh"
|
|
||||||
|
|
||||||
- name: Build, Package & Upload sourcemaps
|
|
||||||
working-directory: apps/web
|
|
||||||
run: "./scripts/ci_package.sh"
|
|
||||||
env:
|
|
||||||
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
|
|
||||||
SENTRY_DSN: ${{ secrets.SENTRY_DSN }}
|
|
||||||
SENTRY_URL: ${{ secrets.SENTRY_URL }}
|
|
||||||
SENTRY_ORG: element
|
|
||||||
SENTRY_PROJECT: riot-web
|
|
||||||
# We only deploy the latest bundles to Cloudflare Pages and use _redirects to fallback to R2 for
|
|
||||||
# older ones. This redirect means that 'self' is insufficient in the CSP,
|
|
||||||
# and we have to add the R2 URL.
|
|
||||||
# Once Cloudflare redirects support proxying mode we will be able to ditch this.
|
|
||||||
# See Proxying in support table at https://developers.cloudflare.com/pages/platform/redirects
|
|
||||||
CSP_EXTRA_SOURCE: ${{ env.R2_PUBLIC_URL }}
|
|
||||||
|
|
||||||
- run: mv dist/element-*.tar.gz dist/develop.tar.gz
|
|
||||||
working-directory: apps/web
|
|
||||||
|
|
||||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
||||||
with:
|
|
||||||
name: webapp
|
|
||||||
path: apps/web/dist/develop.tar.gz
|
|
||||||
retention-days: 1
|
|
||||||
|
|
||||||
- name: Extract webapp
|
|
||||||
run: |
|
|
||||||
mkdir _deploy
|
|
||||||
tar xf apps/web/dist/develop.tar.gz -C _deploy --strip-components=1
|
|
||||||
|
|
||||||
- name: Copy config
|
|
||||||
run: cp apps/web/element.io/develop/config.json _deploy/config.json
|
|
||||||
|
|
||||||
- name: Populate 404.html
|
|
||||||
run: echo "404 Not Found" > _deploy/404.html
|
|
||||||
|
|
||||||
- name: Populate _headers
|
|
||||||
run: cp .github/cfp_headers _deploy/_headers
|
|
||||||
|
|
||||||
# Redirect requests for the develop tarball and the historical bundles to R2
|
|
||||||
# We find the latest 100 bundle.css files and add their bundles to the redirects file
|
|
||||||
# S3 has no sane way to get the age of a directory as they don't really exist
|
|
||||||
- name: Populate _redirects
|
|
||||||
run: |
|
|
||||||
{
|
|
||||||
echo "/develop.tar.gz $R2_PUBLIC_URL/develop.tar.gz 301"
|
|
||||||
aws s3api --region auto --endpoint-url $R2_URL list-objects-v2 --bucket $R2_BUCKET \
|
|
||||||
--query "sort_by(Contents[?ends_with(Key, '/bundle.css')], &LastModified)[-100:].Key" \
|
|
||||||
--prefix "bundles/" | jq -r '.[]' | grep -oE '[^\"].*\/\s*' | while read -r path ; do
|
|
||||||
echo "/${path}* $R2_PUBLIC_URL/${path}:splat 301"
|
|
||||||
done
|
|
||||||
} | tee _deploy/_redirects
|
|
||||||
env:
|
|
||||||
AWS_ACCESS_KEY_ID: ${{ secrets.CF_R2_ACCESS_KEY_ID }}
|
|
||||||
AWS_SECRET_ACCESS_KEY: ${{ secrets.CF_R2_TOKEN }}
|
|
||||||
|
|
||||||
# We may be trying to deploy the same webapp bundles again, we need to ensure that the live bundles
|
|
||||||
# are not present in the _redirects file and instead accessed directly from Cloudflare Pages.
|
|
||||||
- name: Trim _redirects
|
|
||||||
working-directory: _deploy
|
|
||||||
run: |
|
|
||||||
find bundles -type d -mindepth 1 -maxdepth 1 -exec sed -i "\:{}:d" _redirects \;
|
|
||||||
|
|
||||||
- name: Wait for other steps to succeed
|
|
||||||
uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork
|
|
||||||
with:
|
|
||||||
ref: ${{ github.sha }}
|
|
||||||
running-workflow-name: "Build & Deploy develop.element.io"
|
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
wait-interval: 10
|
|
||||||
check-regexp: ^((?!SonarCloud|SonarQube|issue|board|label|Release|prepare|GitHub Pages|Upload|Netlify|Report).)*$
|
|
||||||
|
|
||||||
# We keep the latest develop.tar.gz on R2 instead of relying on the github artifact uploaded earlier
|
|
||||||
# as the expires after 24h and requires auth to download.
|
|
||||||
# Element Desktop's fetch script uses this tarball to fetch latest develop to build Nightlies.
|
|
||||||
# Checksum algorithm specified as per https://developers.cloudflare.com/r2/examples/aws/aws-cli/
|
|
||||||
- name: Deploy to R2
|
|
||||||
run: |
|
|
||||||
aws s3 cp apps/web/dist/develop.tar.gz s3://$R2_BUCKET/develop.tar.gz --endpoint-url $R2_URL --region=auto --checksum-algorithm CRC32
|
|
||||||
aws s3 cp _deploy/ s3://$R2_BUCKET/ --recursive --endpoint-url $R2_URL --region=auto --checksum-algorithm CRC32
|
|
||||||
env:
|
|
||||||
AWS_ACCESS_KEY_ID: ${{ secrets.CF_R2_ACCESS_KEY_ID }}
|
|
||||||
AWS_SECRET_ACCESS_KEY: ${{ secrets.CF_R2_TOKEN }}
|
|
||||||
|
|
||||||
- name: Deploy to Cloudflare Pages
|
|
||||||
id: cfp
|
|
||||||
uses: cloudflare/pages-action@f0a1cd58cd66095dee69bfa18fa5efd1dde93bca # v1
|
|
||||||
with:
|
|
||||||
apiToken: ${{ secrets.CF_PAGES_TOKEN }}
|
|
||||||
accountId: ${{ secrets.CF_PAGES_ACCOUNT_ID }}
|
|
||||||
projectName: element-web-develop
|
|
||||||
directory: _deploy
|
|
||||||
gitHubToken: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
|
|
||||||
- run: |
|
|
||||||
echo "Deployed to ${STEPS_CFP_OUTPUTS_URL}" >> $GITHUB_STEP_SUMMARY
|
|
||||||
env:
|
|
||||||
STEPS_CFP_OUTPUTS_URL: ${{ steps.cfp.outputs.url }}
|
|
||||||
@@ -1,75 +0,0 @@
|
|||||||
name: CD # Continuous Delivery
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches: [master, staging, develop]
|
|
||||||
paths:
|
|
||||||
- "**/Dockerfile"
|
|
||||||
- "**/dockerbuild"
|
|
||||||
- "**/docker"
|
|
||||||
- "**/docker-*"
|
|
||||||
- "pnpm-lock.yaml"
|
|
||||||
|
|
||||||
concurrency: ${{ github.workflow }}-${{ github.ref_name }}
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
env:
|
|
||||||
NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
docker:
|
|
||||||
name: Docker Bake
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
permissions:
|
|
||||||
id-token: write # needed for signing the images with GitHub OIDC Token
|
|
||||||
packages: write # needed for publishing packages to GHCR
|
|
||||||
# Needed for nx-set-shas
|
|
||||||
contents: read
|
|
||||||
actions: read
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- name: Install Cosign
|
|
||||||
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
|
|
||||||
|
|
||||||
- name: Set up QEMU
|
|
||||||
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4
|
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
|
||||||
id: builder
|
|
||||||
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
node-version-file: package.json
|
|
||||||
cache: "pnpm"
|
|
||||||
|
|
||||||
- name: Install Deps
|
|
||||||
run: "pnpm install --frozen-lockfile"
|
|
||||||
|
|
||||||
- name: Login to GitHub Container Registry
|
|
||||||
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4
|
|
||||||
with:
|
|
||||||
registry: ghcr.io
|
|
||||||
username: ${{ github.repository_owner }}
|
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
|
|
||||||
- run: pnpm nx run-many --nxBail -t docker:build
|
|
||||||
id: build
|
|
||||||
env:
|
|
||||||
INPUT_PUSH: true
|
|
||||||
INPUT_LOAD: false
|
|
||||||
INPUT_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
INPUT_BUILDER: ${{ steps.builder.outputs.name }}
|
|
||||||
|
|
||||||
- name: Sign the images with GitHub OIDC token
|
|
||||||
run: |
|
|
||||||
shopt -s globstar
|
|
||||||
|
|
||||||
for FILE in ./node_modules/.cache/nx-container/**/metadata; do
|
|
||||||
TARGET=$(jq -r '(.["image.name"] | split(",") | last) + "@" + .["containerimage.digest"]' "$FILE")
|
|
||||||
echo "Signing $TARGET..."
|
|
||||||
cosign sign --yes "$TARGET"
|
|
||||||
done
|
|
||||||
@@ -1,101 +0,0 @@
|
|||||||
# Manual deploy workflow for deploying to app.element.io & staging.element.io
|
|
||||||
# Runs automatically for staging.element.io when an RC or Release is published
|
|
||||||
# Note: Does *NOT* run automatically for app.element.io so that it gets tested on staging.element.io beforehand
|
|
||||||
name: Deploy release
|
|
||||||
run-name: Deploy ${{ github.ref_name }} to ${{ inputs.site || 'staging.element.io' }}
|
|
||||||
on:
|
|
||||||
release:
|
|
||||||
types: [published]
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
site:
|
|
||||||
description: Which site to deploy to
|
|
||||||
required: true
|
|
||||||
default: staging.element.io
|
|
||||||
type: choice
|
|
||||||
options:
|
|
||||||
- staging.element.io
|
|
||||||
- app.element.io
|
|
||||||
skip-checks:
|
|
||||||
description: Skip CI on the tagged commit
|
|
||||||
required: true
|
|
||||||
default: false
|
|
||||||
type: boolean
|
|
||||||
concurrency: ${{ inputs.site || 'staging.element.io' }}
|
|
||||||
permissions: {}
|
|
||||||
jobs:
|
|
||||||
deploy:
|
|
||||||
name: "Deploy to Cloudflare Pages"
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
environment: ${{ inputs.site || 'staging.element.io' }}
|
|
||||||
permissions:
|
|
||||||
checks: read
|
|
||||||
deployments: write
|
|
||||||
env:
|
|
||||||
SITE: ${{ inputs.site || 'staging.element.io' }}
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- name: Load GPG key
|
|
||||||
run: |
|
|
||||||
curl https://packages.element.io/element-release-key.gpg | gpg --import
|
|
||||||
gpg -k "$GPG_FINGERPRINT"
|
|
||||||
env:
|
|
||||||
GPG_FINGERPRINT: ${{ vars.GPG_FINGERPRINT }}
|
|
||||||
|
|
||||||
- name: Check current version on deployment
|
|
||||||
id: current_version
|
|
||||||
run: |
|
|
||||||
version=$(curl -s https://$SITE/version)
|
|
||||||
echo "version=${version#v}" >> $GITHUB_OUTPUT
|
|
||||||
|
|
||||||
# The current version bundle melding dance is skipped if the version we're deploying is the same
|
|
||||||
# as then we're just doing a re-deploy of the same version with potentially different configs.
|
|
||||||
- name: Download current version for its old bundles
|
|
||||||
id: current_download
|
|
||||||
if: steps.current_version.outputs.version != github.ref_name
|
|
||||||
uses: ./.github/actions/download-verify-element-tarball
|
|
||||||
with:
|
|
||||||
tag: v${{ steps.current_version.outputs.version }}
|
|
||||||
out-file-path: _current_version
|
|
||||||
|
|
||||||
- name: Download target version
|
|
||||||
uses: ./.github/actions/download-verify-element-tarball
|
|
||||||
with:
|
|
||||||
tag: ${{ github.ref_name }}
|
|
||||||
out-file-path: _deploy
|
|
||||||
|
|
||||||
- name: Merge current bundles into target
|
|
||||||
if: steps.current_download.outcome == 'success'
|
|
||||||
run: cp -vnpr _current_version/bundles/* _deploy/bundles/
|
|
||||||
|
|
||||||
- name: Copy config
|
|
||||||
run: cp apps/web/element.io/app/config.json _deploy/config.json
|
|
||||||
|
|
||||||
- name: Populate 404.html
|
|
||||||
run: echo "404 Not Found" > _deploy/404.html
|
|
||||||
|
|
||||||
- name: Populate _headers
|
|
||||||
run: cp .github/cfp_headers _deploy/_headers
|
|
||||||
|
|
||||||
- name: Wait for other steps to succeed
|
|
||||||
uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork
|
|
||||||
if: inputs.skip-checks != true
|
|
||||||
with:
|
|
||||||
ref: ${{ github.sha }}
|
|
||||||
running-workflow-name: "Deploy to Cloudflare Pages"
|
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
wait-interval: 10
|
|
||||||
check-regexp: ^((?!SonarCloud|SonarQube|issue|board|label|Release|prepare|GitHub Pages).)*$
|
|
||||||
|
|
||||||
- name: Deploy to Cloudflare Pages
|
|
||||||
uses: cloudflare/pages-action@f0a1cd58cd66095dee69bfa18fa5efd1dde93bca # v1
|
|
||||||
with:
|
|
||||||
apiToken: ${{ secrets.CF_PAGES_TOKEN }}
|
|
||||||
accountId: ${{ secrets.CF_PAGES_ACCOUNT_ID }}
|
|
||||||
projectName: ${{ env.SITE == 'staging.element.io' && 'element-web-staging' || 'element-web' }}
|
|
||||||
directory: _deploy
|
|
||||||
gitHubToken: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
branch: main
|
|
||||||
@@ -1,181 +0,0 @@
|
|||||||
name: Docker
|
|
||||||
on:
|
|
||||||
workflow_dispatch: {}
|
|
||||||
push:
|
|
||||||
tags: [v*]
|
|
||||||
pull_request: {}
|
|
||||||
schedule:
|
|
||||||
# This job can take a while, and we have usage limits, so just publish develop only twice a day
|
|
||||||
- cron: "0 7/12 * * *"
|
|
||||||
concurrency: ${{ github.workflow }}-${{ github.ref_name }}
|
|
||||||
permissions: {}
|
|
||||||
jobs:
|
|
||||||
buildx:
|
|
||||||
name: Docker Buildx
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
environment: ${{ github.event_name != 'pull_request' && 'dockerhub' || '' }}
|
|
||||||
permissions:
|
|
||||||
id-token: write # needed for signing the images with GitHub OIDC Token
|
|
||||||
packages: write # needed for publishing packages to GHCR
|
|
||||||
env:
|
|
||||||
TEST_TAG: vectorim/element-web:test
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
fetch-depth: 0 # needed for docker-package to be able to calculate the version
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- name: Install Cosign
|
|
||||||
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
|
|
||||||
- name: Set up QEMU
|
|
||||||
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4
|
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
|
||||||
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
|
|
||||||
with:
|
|
||||||
install: true
|
|
||||||
|
|
||||||
- name: Build and load
|
|
||||||
id: test-build
|
|
||||||
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7
|
|
||||||
with:
|
|
||||||
context: .
|
|
||||||
file: apps/web/Dockerfile
|
|
||||||
load: true
|
|
||||||
|
|
||||||
- name: Test the image
|
|
||||||
env:
|
|
||||||
IMAGEID: ${{ steps.test-build.outputs.imageid }}
|
|
||||||
timeout-minutes: 2
|
|
||||||
run: |
|
|
||||||
set -x
|
|
||||||
|
|
||||||
# Make a fake module to test the image
|
|
||||||
MODULE_PATH="modules/module_name/index.js"
|
|
||||||
mkdir -p $(dirname $MODULE_PATH)
|
|
||||||
echo 'alert("Testing");' > $MODULE_PATH
|
|
||||||
|
|
||||||
# Spin up a container of the image
|
|
||||||
ELEMENT_WEB_PORT=8181
|
|
||||||
CONTAINER_ID=$(
|
|
||||||
docker run \
|
|
||||||
--rm \
|
|
||||||
-e "ELEMENT_WEB_PORT=$ELEMENT_WEB_PORT" \
|
|
||||||
-dp "$ELEMENT_WEB_PORT:$ELEMENT_WEB_PORT" \
|
|
||||||
-v $(pwd)/modules:/modules \
|
|
||||||
"$IMAGEID" \
|
|
||||||
)
|
|
||||||
|
|
||||||
# Run some smoke tests
|
|
||||||
wget --retry-connrefused --tries=5 -q --wait=3 --spider "http://localhost:$ELEMENT_WEB_PORT/modules/module_name/index.js"
|
|
||||||
MODULE_0=$(curl "http://localhost:$ELEMENT_WEB_PORT/config.json" | jq -r .modules[0])
|
|
||||||
test "$MODULE_0" = "/${MODULE_PATH}"
|
|
||||||
|
|
||||||
# Check healthcheck
|
|
||||||
until test "$(docker inspect -f {{.State.Health.Status}} $CONTAINER_ID)" == "healthy"; do
|
|
||||||
sleep 1
|
|
||||||
done
|
|
||||||
|
|
||||||
# Clean up
|
|
||||||
docker stop "$CONTAINER_ID"
|
|
||||||
|
|
||||||
- name: Docker meta
|
|
||||||
id: meta
|
|
||||||
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
with:
|
|
||||||
images: |
|
|
||||||
vectorim/element-web
|
|
||||||
ghcr.io/element-hq/element-web
|
|
||||||
oci-push.vpn.infra.element.io/element-web
|
|
||||||
tags: |
|
|
||||||
type=ref,event=branch
|
|
||||||
type=ref,event=tag
|
|
||||||
flavor: |
|
|
||||||
latest=${{ contains(github.ref_name, '-rc.') && 'false' || 'auto' }}
|
|
||||||
|
|
||||||
- name: Login to Docker Hub
|
|
||||||
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
with:
|
|
||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
||||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
||||||
|
|
||||||
- name: Login to GitHub Container Registry
|
|
||||||
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
with:
|
|
||||||
registry: ghcr.io
|
|
||||||
username: ${{ github.repository_owner }}
|
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
|
|
||||||
- name: Connect to Tailscale
|
|
||||||
uses: tailscale/github-action@306e68a486fd2350f2bfc3b19fcd143891a4a2d8 # v4
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
with:
|
|
||||||
oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }}
|
|
||||||
audience: ${{ secrets.TS_AUDIENCE }}
|
|
||||||
tags: tag:github-actions
|
|
||||||
|
|
||||||
- name: Compute vault jwt role name
|
|
||||||
id: vault-jwt-role
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
run: |
|
|
||||||
echo "role_name=github_service_management_$( echo "${{ github.repository }}" | sed -r 's|[/-]|_|g')" | tee -a "$GITHUB_OUTPUT"
|
|
||||||
|
|
||||||
- name: Get team registry token
|
|
||||||
id: import-secrets
|
|
||||||
uses: hashicorp/vault-action@4c06c5ccf5c0761b6029f56cfb1dcf5565918a3b # v3
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
with:
|
|
||||||
url: https://vault.infra.ci.i.element.dev
|
|
||||||
role: ${{ steps.vault-jwt-role.outputs.role_name }}
|
|
||||||
path: service-management/github-actions
|
|
||||||
jwtGithubAudience: https://vault.infra.ci.i.element.dev
|
|
||||||
method: jwt
|
|
||||||
secrets: |
|
|
||||||
services/web-repositories/secret/data/oci.element.io username | OCI_USERNAME ;
|
|
||||||
services/web-repositories/secret/data/oci.element.io password | OCI_PASSWORD ;
|
|
||||||
|
|
||||||
- name: Login to oci.element.io Registry
|
|
||||||
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
with:
|
|
||||||
registry: oci-push.vpn.infra.element.io
|
|
||||||
username: ${{ steps.import-secrets.outputs.OCI_USERNAME }}
|
|
||||||
password: ${{ steps.import-secrets.outputs.OCI_PASSWORD }}
|
|
||||||
|
|
||||||
- name: Build and push
|
|
||||||
id: build-and-push
|
|
||||||
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
with:
|
|
||||||
context: .
|
|
||||||
file: apps/web/Dockerfile
|
|
||||||
push: true
|
|
||||||
platforms: linux/amd64,linux/arm64
|
|
||||||
tags: ${{ steps.meta.outputs.tags }}
|
|
||||||
labels: ${{ steps.meta.outputs.labels }}
|
|
||||||
|
|
||||||
- name: Sign the images with GitHub OIDC Token
|
|
||||||
env:
|
|
||||||
DIGEST: ${{ steps.build-and-push.outputs.digest }}
|
|
||||||
TAGS: ${{ steps.meta.outputs.tags }}
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
run: |
|
|
||||||
images=""
|
|
||||||
for tag in ${TAGS}; do
|
|
||||||
images+="${tag}@${DIGEST} "
|
|
||||||
done
|
|
||||||
cosign sign --yes ${images}
|
|
||||||
|
|
||||||
- name: Update repo description
|
|
||||||
uses: peter-evans/dockerhub-description@1b9a80c056b620d92cedb9d9b5a223409c68ddfa # v5
|
|
||||||
if: github.event_name != 'pull_request'
|
|
||||||
continue-on-error: true
|
|
||||||
with:
|
|
||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
||||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
||||||
repository: vectorim/element-web
|
|
||||||
@@ -1,55 +0,0 @@
|
|||||||
name: Deploy documentation
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches: [develop]
|
|
||||||
workflow_dispatch: {}
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
concurrency:
|
|
||||||
group: "pages"
|
|
||||||
cancel-in-progress: false
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
name: GitHub Pages
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
with:
|
|
||||||
package_json_file: package.json
|
|
||||||
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
cache: "pnpm"
|
|
||||||
cache-dependency-path: pnpm-lock.yaml
|
|
||||||
node-version: "lts/*"
|
|
||||||
|
|
||||||
- name: Fetch layered build
|
|
||||||
run: ./scripts/layered.sh
|
|
||||||
|
|
||||||
- name: Build docs
|
|
||||||
run: pnpm run docs:build
|
|
||||||
|
|
||||||
- name: Upload artifact
|
|
||||||
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5
|
|
||||||
with:
|
|
||||||
path: ./docs/.vitepress/dist
|
|
||||||
|
|
||||||
deploy:
|
|
||||||
environment:
|
|
||||||
name: github-pages
|
|
||||||
url: ${{ steps.deployment.outputs.page_url }}
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
permissions:
|
|
||||||
pages: write
|
|
||||||
id-token: write
|
|
||||||
needs: build
|
|
||||||
steps:
|
|
||||||
- name: Deploy to GitHub Pages
|
|
||||||
id: deployment
|
|
||||||
uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5
|
|
||||||
@@ -1,157 +0,0 @@
|
|||||||
# For duplicate issues, ensure the close type is right (not planned), update it if not
|
|
||||||
# For all closed (completed) issues, cascade the closure onto any referenced rageshakes
|
|
||||||
# For all closed (not planned) issues, comment on rageshakes to move them into the canonical issue if one exists
|
|
||||||
on:
|
|
||||||
issues:
|
|
||||||
types: [closed]
|
|
||||||
permissions: {} # We use ELEMENT_BOT_TOKEN instead
|
|
||||||
jobs:
|
|
||||||
tidy:
|
|
||||||
name: Tidy closed issues
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
|
|
||||||
id: main
|
|
||||||
with:
|
|
||||||
# PAT needed as the GITHUB_TOKEN won't be able to see cross-references from other orgs (matrix-org)
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
script: |
|
|
||||||
const variables = {
|
|
||||||
owner: context.repo.owner,
|
|
||||||
name: context.repo.repo,
|
|
||||||
number: context.issue.number,
|
|
||||||
};
|
|
||||||
|
|
||||||
const query = `query($owner:String!, $name:String!, $number:Int!) {
|
|
||||||
repository(owner: $owner, name: $name) {
|
|
||||||
issue(number: $number) {
|
|
||||||
stateReason,
|
|
||||||
timelineItems(first: 100, itemTypes: [MARKED_AS_DUPLICATE_EVENT, UNMARKED_AS_DUPLICATE_EVENT, CROSS_REFERENCED_EVENT]) {
|
|
||||||
edges {
|
|
||||||
node {
|
|
||||||
__typename
|
|
||||||
... on MarkedAsDuplicateEvent {
|
|
||||||
canonical {
|
|
||||||
... on Issue {
|
|
||||||
repository {
|
|
||||||
nameWithOwner
|
|
||||||
}
|
|
||||||
number
|
|
||||||
}
|
|
||||||
... on PullRequest {
|
|
||||||
repository {
|
|
||||||
nameWithOwner
|
|
||||||
}
|
|
||||||
number
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
... on UnmarkedAsDuplicateEvent {
|
|
||||||
canonical {
|
|
||||||
... on Issue {
|
|
||||||
repository {
|
|
||||||
nameWithOwner
|
|
||||||
}
|
|
||||||
number
|
|
||||||
}
|
|
||||||
... on PullRequest {
|
|
||||||
repository {
|
|
||||||
nameWithOwner
|
|
||||||
}
|
|
||||||
number
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
... on CrossReferencedEvent {
|
|
||||||
source {
|
|
||||||
... on Issue {
|
|
||||||
repository {
|
|
||||||
nameWithOwner
|
|
||||||
}
|
|
||||||
number
|
|
||||||
}
|
|
||||||
... on PullRequest {
|
|
||||||
repository {
|
|
||||||
nameWithOwner
|
|
||||||
}
|
|
||||||
number
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}`;
|
|
||||||
|
|
||||||
const result = await github.graphql(query, variables);
|
|
||||||
const { stateReason, timelineItems: { edges } } = result.repository.issue;
|
|
||||||
|
|
||||||
const RAGESHAKE_OWNER = "matrix-org";
|
|
||||||
const RAGESHAKE_REPO = "element-web-rageshakes";
|
|
||||||
const rageshakes = new Set();
|
|
||||||
const duplicateOf = new Set();
|
|
||||||
|
|
||||||
console.log("Edges: ", JSON.stringify(edges));
|
|
||||||
|
|
||||||
for (const { node } of edges) {
|
|
||||||
switch(node.__typename) {
|
|
||||||
case "MarkedAsDuplicateEvent":
|
|
||||||
duplicateOf.add(node.canonical.repository.nameWithOwner + "#" + node.canonical.number);
|
|
||||||
break;
|
|
||||||
case "UnmarkedAsDuplicateEvent":
|
|
||||||
duplicateOf.remove(node.canonical.repository.nameWithOwner + "#" + node.canonical.number);
|
|
||||||
break;
|
|
||||||
case "CrossReferencedEvent":
|
|
||||||
if (node.source.repository.nameWithOwner === (RAGESHAKE_OWNER + "/" + RAGESHAKE_REPO)) {
|
|
||||||
rageshakes.add(node.source.number);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
console.log("Duplicate of: ", duplicateOf);
|
|
||||||
console.log("Found rageshakes: ", rageshakes);
|
|
||||||
|
|
||||||
if (duplicateOf.size) {
|
|
||||||
const body = Array.from(duplicateOf).join("\n");
|
|
||||||
|
|
||||||
// Comment on all rageshakes to create relationship to the issue this was closed as duplicate of
|
|
||||||
for (const rageshake of rageshakes) {
|
|
||||||
github.rest.issues.createComment({
|
|
||||||
owner: RAGESHAKE_OWNER,
|
|
||||||
repo: RAGESHAKE_REPO,
|
|
||||||
issue_number: rageshake,
|
|
||||||
body,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
// Duplicate was closed with wrong reason, fix it
|
|
||||||
if (stateReason === "COMPLETED") {
|
|
||||||
core.setOutput("closeAsNotPlanned", "true");
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
// This issue was closed, close all related rageshakes
|
|
||||||
for (const rageshake of rageshakes) {
|
|
||||||
github.rest.issues.update({
|
|
||||||
owner: RAGESHAKE_OWNER,
|
|
||||||
repo: RAGESHAKE_REPO,
|
|
||||||
issue_number: rageshake,
|
|
||||||
state: "closed",
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
- uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
|
|
||||||
name: Close duplicate as Not Planned
|
|
||||||
if: steps.main.outputs.closeAsNotPlanned
|
|
||||||
with:
|
|
||||||
# We do this step separately, and with the default token so as to not re-trigger this workflow when re-closing
|
|
||||||
script: |
|
|
||||||
await github.graphql(`mutation($id:ID!) {
|
|
||||||
closeIssue(input: { issueId:$id, stateReason:NOT_PLANNED }) {
|
|
||||||
clientMutationId
|
|
||||||
}
|
|
||||||
}`, {
|
|
||||||
id: context.payload.issue.node_id,
|
|
||||||
});
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
name: Localazy Download
|
|
||||||
on:
|
|
||||||
workflow_dispatch: {}
|
|
||||||
schedule:
|
|
||||||
- cron: "0 6 * * 1,3,5" # Every Monday, Wednesday and Friday at 6am UTC
|
|
||||||
permissions:
|
|
||||||
pull-requests: write # needed to auto-approve PRs
|
|
||||||
jobs:
|
|
||||||
download:
|
|
||||||
uses: matrix-org/matrix-web-i18n/.github/workflows/localazy_download.yaml@6eda3835118f3bc3fb658a1a3c20b7da9d16ae42
|
|
||||||
with:
|
|
||||||
packageManager: pnpm
|
|
||||||
secrets:
|
|
||||||
ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
name: Localazy Upload
|
|
||||||
on:
|
|
||||||
workflow_dispatch: {}
|
|
||||||
push:
|
|
||||||
branches: [develop]
|
|
||||||
paths:
|
|
||||||
- "apps/web/src/i18n/strings/en_EN.json"
|
|
||||||
- "packages/shared-components/src/i18n/strings/en_EN.json"
|
|
||||||
permissions: {} # No permissions needed
|
|
||||||
jobs:
|
|
||||||
upload:
|
|
||||||
uses: matrix-org/matrix-web-i18n/.github/workflows/localazy_upload.yaml@6eda3835118f3bc3fb658a1a3c20b7da9d16ae42
|
|
||||||
secrets:
|
|
||||||
LOCALAZY_WRITE_KEY: ${{ secrets.LOCALAZY_WRITE_KEY }}
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
# Tweaks the behaviour of Merge Queue to skip certain checks
|
|
||||||
name: Merge Queue tweaks
|
|
||||||
on:
|
|
||||||
merge_group:
|
|
||||||
types: [checks_requested]
|
|
||||||
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }}
|
|
||||||
cancel-in-progress: true
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
run:
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
permissions:
|
|
||||||
statuses: write
|
|
||||||
steps:
|
|
||||||
# This is only needed as license/cla at time of writing seems to be extraordinarily flaky
|
|
||||||
# and Github doesn't support conditional checks between PR & merge queue.
|
|
||||||
# This is fine to do as a PR won't make it to merge queue until it has license/cla passing.
|
|
||||||
- name: Skip license/cla on merge queues
|
|
||||||
uses: guibranco/github-status-action-v2@9bfa8773cdbdc6c185747fd43cd7faa9d7c32f09
|
|
||||||
with:
|
|
||||||
authToken: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
state: success
|
|
||||||
context: license/cla
|
|
||||||
sha: ${{ github.sha }}
|
|
||||||
target_url: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}
|
|
||||||
@@ -1,53 +0,0 @@
|
|||||||
# Triggers after the layered build has finished, taking the artifact
|
|
||||||
# and uploading it to netlify
|
|
||||||
name: Upload Preview Build to Netlify
|
|
||||||
on:
|
|
||||||
# Privilege escalation necessary to publish to Netlify
|
|
||||||
# 🚨 We must not execute any checked out code here.
|
|
||||||
workflow_run: # zizmor: ignore[dangerous-triggers]
|
|
||||||
workflows: ["Build"]
|
|
||||||
types:
|
|
||||||
- completed
|
|
||||||
jobs:
|
|
||||||
deploy:
|
|
||||||
if: github.event.workflow_run.conclusion != 'cancelled' && github.event.workflow_run.event == 'pull_request'
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
environment: Netlify
|
|
||||||
permissions:
|
|
||||||
actions: read
|
|
||||||
deployments: write
|
|
||||||
steps:
|
|
||||||
- name: 📝 Create Deployment
|
|
||||||
uses: bobheadxi/deployments@648679e8e4915b27893bd7dbc35cb504dc915bc8 # v1
|
|
||||||
id: deployment
|
|
||||||
with:
|
|
||||||
step: start
|
|
||||||
token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
env: Netlify
|
|
||||||
ref: ${{ github.event.workflow_run.head_sha }}
|
|
||||||
desc: |
|
|
||||||
Do you trust the author of this PR? Maybe this build will steal your keys or give you malware.
|
|
||||||
Exercise caution. Use test accounts.
|
|
||||||
|
|
||||||
- name: 📥 Download artifact
|
|
||||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
||||||
with:
|
|
||||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
run-id: ${{ github.event.workflow_run.id }}
|
|
||||||
name: webapp-ubuntu-24.04
|
|
||||||
path: webapp
|
|
||||||
|
|
||||||
- name: 📤 Deploy to Netlify
|
|
||||||
uses: matrix-org/netlify-pr-preview@9805cd123fc9a7e421e35340a05e1ebc5dee46b5 # v3
|
|
||||||
with:
|
|
||||||
path: webapp
|
|
||||||
owner: ${{ github.event.workflow_run.head_repository.owner.login }}
|
|
||||||
branch: ${{ github.event.workflow_run.head_branch }}
|
|
||||||
revision: ${{ github.event.workflow_run.head_sha }}
|
|
||||||
token: ${{ secrets.NETLIFY_AUTH_TOKEN }}
|
|
||||||
site_id: ${{ vars.NETLIFY_SITE_ID }}
|
|
||||||
deployment_env: ${{ steps.deployment.outputs.env }}
|
|
||||||
deployment_id: ${{ steps.deployment.outputs.deployment_id }}
|
|
||||||
desc: |
|
|
||||||
Do you trust the author of this PR? Maybe this build will steal your keys or give you malware.
|
|
||||||
Exercise caution. Use test accounts.
|
|
||||||
@@ -1,47 +0,0 @@
|
|||||||
name: Publish npm package
|
|
||||||
run-name: Publish ${{ inputs.package }}
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
package:
|
|
||||||
description: Which package to release
|
|
||||||
required: true
|
|
||||||
type: choice
|
|
||||||
options:
|
|
||||||
- playwright-common
|
|
||||||
- shared-components
|
|
||||||
- module-api
|
|
||||||
|
|
||||||
concurrency: release
|
|
||||||
jobs:
|
|
||||||
publish:
|
|
||||||
name: "Publish"
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
id-token: write
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: 🧮 Checkout code
|
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- name: 🔧 Set up node environment
|
|
||||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
cache: "pnpm"
|
|
||||||
node-version-file: ".node-version"
|
|
||||||
registry-url: "https://registry.npmjs.org"
|
|
||||||
|
|
||||||
# Ensure npm 11.5.1 or later is installed
|
|
||||||
- name: Update npm
|
|
||||||
run: npm install -g npm@latest
|
|
||||||
|
|
||||||
- name: 🛠️ Install dependencies
|
|
||||||
run: pnpm install --frozen-lockfile
|
|
||||||
|
|
||||||
- name: 🚀 Publish to npm
|
|
||||||
working-directory: packages/${{ inputs.package }}
|
|
||||||
run: npm publish --access public --provenance
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
name: Pull Request
|
|
||||||
on:
|
|
||||||
# Privilege escalation necessary access members of the review teams
|
|
||||||
# 🚨 We must not execute any checked out code here, and be careful around use of user-controlled inputs.
|
|
||||||
pull_request_target: # zizmor: ignore[dangerous-triggers]
|
|
||||||
types: [opened, edited, labeled, unlabeled, synchronize]
|
|
||||||
merge_group:
|
|
||||||
types: [checks_requested]
|
|
||||||
permissions: {}
|
|
||||||
jobs:
|
|
||||||
action:
|
|
||||||
uses: matrix-org/matrix-js-sdk/.github/workflows/pull_request.yaml@develop # zizmor: ignore[unpinned-uses]
|
|
||||||
permissions:
|
|
||||||
pull-requests: write
|
|
||||||
secrets:
|
|
||||||
ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
name: Pull Request Base Branch
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
types: [opened, edited, synchronize]
|
|
||||||
permissions: {} # No permissions required
|
|
||||||
jobs:
|
|
||||||
check_base_branch:
|
|
||||||
name: Check PR base branch
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
|
|
||||||
with:
|
|
||||||
script: |
|
|
||||||
const baseBranch = context.payload.pull_request.base.ref;
|
|
||||||
if (!['develop', 'staging'].includes(baseBranch) && !baseBranch.startsWith('feat/')) {
|
|
||||||
core.setFailed(`Invalid base branch: ${baseBranch}`);
|
|
||||||
}
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
name: Release Drafter
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches: [staging]
|
|
||||||
workflow_dispatch: {}
|
|
||||||
concurrency: ${{ github.workflow }}
|
|
||||||
permissions: {}
|
|
||||||
jobs:
|
|
||||||
draft:
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
uses: matrix-org/matrix-js-sdk/.github/workflows/release-drafter-workflow.yml@develop # zizmor: ignore[unpinned-uses]
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
# Gitflow merge-back master->develop
|
|
||||||
name: Merge master -> develop
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches: [master]
|
|
||||||
concurrency: ${{ github.repository }}-${{ github.workflow }}
|
|
||||||
permissions: {} # We use ELEMENT_BOT_TOKEN instead
|
|
||||||
jobs:
|
|
||||||
merge:
|
|
||||||
uses: matrix-org/matrix-js-sdk/.github/workflows/release-gitflow.yml@develop # zizmor: ignore[unpinned-uses]
|
|
||||||
secrets:
|
|
||||||
ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
with:
|
|
||||||
# This relates to the directory in which to reset dependencies, only web needs this
|
|
||||||
dir: apps/web
|
|
||||||
dependencies: |
|
|
||||||
matrix-js-sdk
|
|
||||||
@@ -1,68 +0,0 @@
|
|||||||
name: Release Process
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
mode:
|
|
||||||
description: What type of release
|
|
||||||
required: true
|
|
||||||
default: rc
|
|
||||||
type: choice
|
|
||||||
options:
|
|
||||||
- rc
|
|
||||||
- final
|
|
||||||
concurrency: ${{ github.workflow }}
|
|
||||||
permissions: {}
|
|
||||||
jobs:
|
|
||||||
release:
|
|
||||||
uses: matrix-org/matrix-js-sdk/.github/workflows/release-make.yml@develop # zizmor: ignore[unpinned-uses]
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
issues: write
|
|
||||||
pull-requests: read
|
|
||||||
id-token: write
|
|
||||||
secrets:
|
|
||||||
ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
|
|
||||||
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
|
|
||||||
with:
|
|
||||||
final: ${{ inputs.mode == 'final' }}
|
|
||||||
gpg-fingerprint: ${{ vars.GPG_FINGERPRINT }}
|
|
||||||
asset-path: dist/*.tar.gz
|
|
||||||
expected-asset-count: 3
|
|
||||||
# Desktop has no dist script so we only target web here
|
|
||||||
dist-dir: apps/web
|
|
||||||
version-dirs: apps/web apps/desktop
|
|
||||||
|
|
||||||
check:
|
|
||||||
name: Post release checks
|
|
||||||
needs: release
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
permissions:
|
|
||||||
checks: read
|
|
||||||
steps:
|
|
||||||
- name: Wait for docker build
|
|
||||||
uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork
|
|
||||||
with:
|
|
||||||
ref: master
|
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
wait-interval: 10
|
|
||||||
check-name: "Docker Buildx"
|
|
||||||
allowed-conclusions: success
|
|
||||||
|
|
||||||
- name: Wait for debian package
|
|
||||||
uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork
|
|
||||||
with:
|
|
||||||
ref: master
|
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
wait-interval: 10
|
|
||||||
check-name: Build package
|
|
||||||
allowed-conclusions: success
|
|
||||||
|
|
||||||
- name: Wait for desktop packaging
|
|
||||||
uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork
|
|
||||||
with:
|
|
||||||
ref: master
|
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
wait-interval: 10
|
|
||||||
check-regexp: Prepare|Linux|macOS|Windows|Deploy|deploy
|
|
||||||
allowed-conclusions: success
|
|
||||||
@@ -1,97 +0,0 @@
|
|||||||
name: Cut branches
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
element-web:
|
|
||||||
description: Prepare element-web
|
|
||||||
required: true
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
matrix-js-sdk:
|
|
||||||
description: Prepare matrix-js-sdk
|
|
||||||
required: true
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
permissions: {} # Uses ELEMENT_BOT_TOKEN instead
|
|
||||||
jobs:
|
|
||||||
checks:
|
|
||||||
name: Sanity checks
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
repo:
|
|
||||||
- matrix-org/matrix-js-sdk
|
|
||||||
- element-hq/element-web
|
|
||||||
uses: matrix-org/matrix-js-sdk/.github/workflows/release-checks.yml@develop # zizmor: ignore[unpinned-uses]
|
|
||||||
secrets:
|
|
||||||
ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
with:
|
|
||||||
repository: ${{ matrix.repo }}
|
|
||||||
|
|
||||||
prepare:
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
needs: checks
|
|
||||||
env:
|
|
||||||
# The order is specified bottom-up to avoid any races for allchange
|
|
||||||
REPOS: matrix-js-sdk element-web
|
|
||||||
steps:
|
|
||||||
- name: Checkout Element Web
|
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
if: inputs.element-web
|
|
||||||
with:
|
|
||||||
repository: element-hq/element-web
|
|
||||||
path: element-web
|
|
||||||
ref: staging
|
|
||||||
fetch-depth: 0
|
|
||||||
fetch-tags: true
|
|
||||||
token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
persist-credentials: true
|
|
||||||
- name: Checkout Matrix JS SDK
|
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
if: inputs.matrix-js-sdk
|
|
||||||
with:
|
|
||||||
repository: matrix-org/matrix-js-sdk
|
|
||||||
path: matrix-js-sdk
|
|
||||||
ref: staging
|
|
||||||
fetch-depth: 0
|
|
||||||
fetch-tags: true
|
|
||||||
token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
persist-credentials: true
|
|
||||||
|
|
||||||
- name: Prepare Git
|
|
||||||
run: |
|
|
||||||
git config --global user.email "releases@riot.im"
|
|
||||||
git config --global user.name "RiotRobot"
|
|
||||||
|
|
||||||
- name: Merge Element Web
|
|
||||||
if: inputs.element-web
|
|
||||||
run: |
|
|
||||||
git -C "element-web" merge origin/develop
|
|
||||||
- name: Merge JS SDK
|
|
||||||
if: inputs.matrix-js-sdk
|
|
||||||
run: |
|
|
||||||
git -C "matrix-js-sdk" merge origin/develop
|
|
||||||
|
|
||||||
- name: Push staging
|
|
||||||
run: for REPO in $REPOS; do [ -d "$REPO" ] && git -C "$REPO" push origin staging; done
|
|
||||||
|
|
||||||
- name: Wait for matrix-js-sdk draft
|
|
||||||
if: inputs.matrix-js-sdk
|
|
||||||
uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork
|
|
||||||
with:
|
|
||||||
ref: staging
|
|
||||||
repo: matrix-org/matrix-js-sdk
|
|
||||||
repo-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
wait-interval: 10
|
|
||||||
check-name: "draft / draft"
|
|
||||||
allowed-conclusions: success
|
|
||||||
|
|
||||||
- name: Wait for element-web draft
|
|
||||||
if: inputs.element-web
|
|
||||||
uses: t3chguy/wait-on-check-action@18541021811b56544d90e0f073401c2b99e249d6 # fork
|
|
||||||
with:
|
|
||||||
ref: staging
|
|
||||||
repo: element-hq/element-web
|
|
||||||
repo-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
wait-interval: 10
|
|
||||||
check-name: "draft / draft"
|
|
||||||
allowed-conclusions: success
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
name: Build shared component storybook
|
|
||||||
on:
|
|
||||||
merge_group: {}
|
|
||||||
pull_request: {}
|
|
||||||
workflow_call: {}
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
doc:
|
|
||||||
name: Build storybook
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: 🧮 Checkout code
|
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- name: 🔧 Pnpm cache
|
|
||||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
cache: "pnpm"
|
|
||||||
node-version-file: package.json
|
|
||||||
|
|
||||||
- name: 🔨 Install dependencies
|
|
||||||
working-directory: packages/shared-components
|
|
||||||
run: "pnpm install --frozen-lockfile"
|
|
||||||
|
|
||||||
- name: 📖 Build Storybook
|
|
||||||
working-directory: packages/shared-components
|
|
||||||
run: pnpm build:storybook
|
|
||||||
|
|
||||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
||||||
with:
|
|
||||||
name: shared-components-storybook
|
|
||||||
path: packages/shared-components/storybook-static
|
|
||||||
retention-days: 1
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
name: Publish shared component storybook
|
|
||||||
on:
|
|
||||||
workflow_dispatch: {}
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- "develop"
|
|
||||||
paths:
|
|
||||||
- "packages/shared-components/**/*"
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
name: Build storybook
|
|
||||||
uses: ./.github/workflows/shared-component-storybook-build.yml
|
|
||||||
|
|
||||||
publish:
|
|
||||||
name: Publish storybook
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
needs: build
|
|
||||||
environment: SharedComponents
|
|
||||||
steps:
|
|
||||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
||||||
with:
|
|
||||||
name: shared-components-storybook
|
|
||||||
path: storybook-static
|
|
||||||
|
|
||||||
- name: 🚀 Deploy to Cloudflare Pages
|
|
||||||
uses: cloudflare/wrangler-action@9acf94ace14e7dc412b076f2c5c20b8ce93c79cd # v3
|
|
||||||
with:
|
|
||||||
apiToken: ${{ secrets.CF_PAGES_TOKEN }}
|
|
||||||
accountId: ${{ secrets.CF_PAGES_ACCOUNT_ID }}
|
|
||||||
command: pages deploy storybook-static --project-name=shared-components-storybook
|
|
||||||
@@ -1,50 +0,0 @@
|
|||||||
# Triggers after the shared component tests have finished,
|
|
||||||
# It uploads the received images and diffs to netlify, printing the URLs to the console
|
|
||||||
name: Upload Shared Component Visual Test Diffs
|
|
||||||
on:
|
|
||||||
# Privilege escalation necessary to deploy to Netlify
|
|
||||||
# 🚨 We must not execute any checked out code here.
|
|
||||||
workflow_run: # zizmor: ignore[dangerous-triggers]
|
|
||||||
workflows: ["Shared Component Visual Tests"]
|
|
||||||
types:
|
|
||||||
- completed
|
|
||||||
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.workflow }}-${{ github.event.workflow_run.head_branch || github.run_id }}
|
|
||||||
cancel-in-progress: ${{ github.event.workflow_run.event == 'pull_request' }}
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
report:
|
|
||||||
if: github.event.workflow_run.conclusion == 'failure'
|
|
||||||
name: Upload Diffs
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
environment: Netlify
|
|
||||||
permissions:
|
|
||||||
actions: read
|
|
||||||
deployments: write
|
|
||||||
steps:
|
|
||||||
- name: Download Diffs
|
|
||||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
||||||
with:
|
|
||||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
run-id: ${{ github.event.workflow_run.id }}
|
|
||||||
name: received-images
|
|
||||||
path: received-images
|
|
||||||
|
|
||||||
- name: Generate Index
|
|
||||||
run: "cd received-images && tree -L 1 --noreport -H '' -o index.html ."
|
|
||||||
|
|
||||||
- name: 📤 Deploy to Netlify
|
|
||||||
uses: matrix-org/netlify-pr-preview@9805cd123fc9a7e421e35340a05e1ebc5dee46b5 # v3
|
|
||||||
with:
|
|
||||||
path: received-images
|
|
||||||
owner: ${{ github.event.workflow_run.head_repository.owner.login }}
|
|
||||||
branch: ${{ github.event.workflow_run.head_branch }}
|
|
||||||
revision: ${{ github.event.workflow_run.head_sha }}
|
|
||||||
token: ${{ secrets.NETLIFY_AUTH_TOKEN }}
|
|
||||||
site_id: ${{ vars.NETLIFY_SITE_ID }}
|
|
||||||
desc: Shared Component Visual Diffs
|
|
||||||
deployment_env: SharedComponentDiffs
|
|
||||||
prefix: "diffs-"
|
|
||||||
@@ -1,60 +0,0 @@
|
|||||||
name: Shared Component Visual Tests
|
|
||||||
on:
|
|
||||||
pull_request: {}
|
|
||||||
merge_group:
|
|
||||||
types: [checks_requested]
|
|
||||||
push:
|
|
||||||
branches: [develop, master]
|
|
||||||
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }}
|
|
||||||
cancel-in-progress: true
|
|
||||||
|
|
||||||
permissions: {} # No permissions required
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
testStorybook:
|
|
||||||
name: "Run Visual Tests"
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
permissions:
|
|
||||||
actions: read
|
|
||||||
issues: read
|
|
||||||
pull-requests: read
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
repository: element-hq/element-web
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
cache: "pnpm"
|
|
||||||
node-version: "lts/*"
|
|
||||||
|
|
||||||
- name: Install dependencies
|
|
||||||
working-directory: packages/shared-components
|
|
||||||
run: pnpm install --frozen-lockfile
|
|
||||||
|
|
||||||
- name: Setup playwright
|
|
||||||
uses: ./.github/actions/setup-playwright
|
|
||||||
with:
|
|
||||||
write-cache: ${{ github.event_name != 'merge_group' }}
|
|
||||||
|
|
||||||
- name: Run Visual tests
|
|
||||||
working-directory: packages/shared-components
|
|
||||||
run: "pnpm test:storybook --run"
|
|
||||||
|
|
||||||
- name: Detect stale screenshots
|
|
||||||
run: |
|
|
||||||
if diff -rq __baselines__ __results__ | grep "^Only in __baselines__"; then
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
working-directory: packages/shared-components/__vis__/linux
|
|
||||||
|
|
||||||
- name: Upload received images & diffs
|
|
||||||
if: always()
|
|
||||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
||||||
with:
|
|
||||||
name: received-images
|
|
||||||
path: packages/shared-components/__vis__/linux
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
name: SonarQube
|
|
||||||
on:
|
|
||||||
# Privilege escalation necessary to call upon SonarCloud
|
|
||||||
# 🚨 We must not execute any checked out code here.
|
|
||||||
workflow_run: # zizmor: ignore[dangerous-triggers]
|
|
||||||
workflows: ["Tests"]
|
|
||||||
types:
|
|
||||||
- completed
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.workflow }}-${{ github.event.workflow_run.head_branch }}
|
|
||||||
cancel-in-progress: true
|
|
||||||
permissions: {}
|
|
||||||
jobs:
|
|
||||||
sonarqube:
|
|
||||||
name: 🩻 SonarQube
|
|
||||||
if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event != 'merge_group'
|
|
||||||
uses: matrix-org/matrix-js-sdk/.github/workflows/sonarcloud.yml@develop # zizmor: ignore[unpinned-uses]
|
|
||||||
permissions:
|
|
||||||
actions: read
|
|
||||||
statuses: write
|
|
||||||
id-token: write # sonar
|
|
||||||
secrets:
|
|
||||||
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
|
|
||||||
ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
with:
|
|
||||||
sharded: true
|
|
||||||
version-pkg-json-dir: ./apps/web
|
|
||||||
@@ -1,133 +0,0 @@
|
|||||||
name: Static Analysis
|
|
||||||
on:
|
|
||||||
pull_request: {}
|
|
||||||
push:
|
|
||||||
branches: [develop, master]
|
|
||||||
merge_group:
|
|
||||||
types: [checks_requested]
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }}
|
|
||||||
cancel-in-progress: true
|
|
||||||
|
|
||||||
env:
|
|
||||||
# This must be set for fetchdep.sh to get the right branch
|
|
||||||
PR_NUMBER: ${{ github.event.pull_request.number }}
|
|
||||||
NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes
|
|
||||||
|
|
||||||
permissions: {} # No permissions required
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
lint:
|
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
matrix:
|
|
||||||
include:
|
|
||||||
- name: Typescript Syntax Check
|
|
||||||
install: layered
|
|
||||||
command: "lint:types"
|
|
||||||
- name: Prettier
|
|
||||||
install: normal
|
|
||||||
command: "lint:prettier"
|
|
||||||
- name: ESLint
|
|
||||||
install: normal
|
|
||||||
command: "lint:js"
|
|
||||||
- name: Style Lint
|
|
||||||
install: normal
|
|
||||||
command: "lint:style"
|
|
||||||
- name: Workflow Lint
|
|
||||||
install: normal
|
|
||||||
command: "lint:workflows"
|
|
||||||
- name: Analyse Dead Code
|
|
||||||
install: normal
|
|
||||||
command: "lint:knip"
|
|
||||||
- name: Rethemendex Check
|
|
||||||
command: "rethemendex"
|
|
||||||
assert-diff: true
|
|
||||||
- name: Docs
|
|
||||||
install: layered
|
|
||||||
command: "docs:build"
|
|
||||||
name: ${{ matrix.name }}
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
if: matrix.install != ''
|
|
||||||
with:
|
|
||||||
cache: "pnpm"
|
|
||||||
node-version: "lts/*"
|
|
||||||
|
|
||||||
- name: Install Dependencies (layered)
|
|
||||||
if: matrix.install == 'layered'
|
|
||||||
run: "./scripts/layered.sh"
|
|
||||||
- name: Install Dependencies (normal)
|
|
||||||
if: matrix.install == 'normal'
|
|
||||||
run: "pnpm install --frozen-lockfile"
|
|
||||||
|
|
||||||
- name: Run ${{ matrix.command }}
|
|
||||||
run: pnpm --if-present run "$CMD" && pnpm -r --if-present run "$CMD"
|
|
||||||
env:
|
|
||||||
CMD: ${{ matrix.command }}
|
|
||||||
|
|
||||||
- name: Assert no changes
|
|
||||||
run: git diff --exit-code
|
|
||||||
if: matrix.assert-diff
|
|
||||||
|
|
||||||
zizmor:
|
|
||||||
name: Zizmor Github Actions lint
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
permissions:
|
|
||||||
security-events: write
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- name: Run zizmor
|
|
||||||
uses: zizmorcore/zizmor-action@b1d7e1fb5de872772f31590499237e7cce841e8e # v0.5.3
|
|
||||||
|
|
||||||
i18n:
|
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
matrix:
|
|
||||||
include:
|
|
||||||
- name: Element Web
|
|
||||||
path: "apps/web"
|
|
||||||
allowed-hardcoded-keys: |
|
|
||||||
console_dev_note
|
|
||||||
labs|element_call_video_rooms
|
|
||||||
labs|feature_disable_call_per_sender_encryption
|
|
||||||
voip|element_call
|
|
||||||
error|invalid_json
|
|
||||||
error|misconfigured
|
|
||||||
welcome|title_element
|
|
||||||
devtools|settings|elementCallUrl
|
|
||||||
labs|sliding_sync_description
|
|
||||||
settings|voip|noise_suppression_description
|
|
||||||
settings|voip|echo_cancellation_description
|
|
||||||
- name: Element Desktop
|
|
||||||
path: "apps/desktop"
|
|
||||||
- name: Shared Components
|
|
||||||
path: "packages/shared-components"
|
|
||||||
name: "i18n Check (${{ matrix.name }})"
|
|
||||||
uses: matrix-org/matrix-web-i18n/.github/workflows/i18n_check.yml@6eda3835118f3bc3fb658a1a3c20b7da9d16ae42
|
|
||||||
permissions:
|
|
||||||
pull-requests: read
|
|
||||||
with:
|
|
||||||
hardcoded-words: "Element"
|
|
||||||
packageManager: pnpm
|
|
||||||
path: ${{ matrix.path }}
|
|
||||||
allowed-hardcoded-keys: ${{ matrix.allowed-hardcoded-keys }}
|
|
||||||
|
|
||||||
# Dummy job to simplify branch protections
|
|
||||||
ci:
|
|
||||||
name: Static Analysis
|
|
||||||
needs: [lint, i18n, zizmor]
|
|
||||||
if: always()
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')
|
|
||||||
run: exit 1
|
|
||||||
@@ -1,24 +0,0 @@
|
|||||||
name: Sync labels
|
|
||||||
on:
|
|
||||||
workflow_dispatch: {}
|
|
||||||
schedule:
|
|
||||||
- cron: "0 1 * * *" # 1am every day
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- develop
|
|
||||||
paths:
|
|
||||||
- .github/labels.yml
|
|
||||||
|
|
||||||
permissions: {} # We use ELEMENT_BOT_TOKEN instead
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
sync-labels:
|
|
||||||
uses: element-hq/element-meta/.github/workflows/sync-labels.yml@7f2f93fb9b52ece7a0998f60e64862aa203c1746
|
|
||||||
with:
|
|
||||||
LABELS: |
|
|
||||||
element-hq/element-meta
|
|
||||||
.github/labels.yml
|
|
||||||
DELETE: true
|
|
||||||
WET: true
|
|
||||||
secrets:
|
|
||||||
ELEMENT_BOT_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
@@ -1,188 +0,0 @@
|
|||||||
name: Tests
|
|
||||||
on:
|
|
||||||
pull_request: {}
|
|
||||||
merge_group:
|
|
||||||
types: [checks_requested]
|
|
||||||
push:
|
|
||||||
branches: [develop, master]
|
|
||||||
workflow_call:
|
|
||||||
inputs:
|
|
||||||
disable_coverage:
|
|
||||||
type: boolean
|
|
||||||
required: false
|
|
||||||
description: "Specify true to skip generating and uploading coverage for tests"
|
|
||||||
matrix-js-sdk-sha:
|
|
||||||
type: string
|
|
||||||
required: false
|
|
||||||
description: "The matrix-js-sdk SHA to use"
|
|
||||||
concurrency:
|
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }}
|
|
||||||
cancel-in-progress: true
|
|
||||||
|
|
||||||
env:
|
|
||||||
ENABLE_COVERAGE: ${{ github.event_name != 'merge_group' && inputs.disable_coverage != 'true' }}
|
|
||||||
# fetchdep.sh needs to know our PR number
|
|
||||||
PR_NUMBER: ${{ github.event.pull_request.number }}
|
|
||||||
NX_DEFAULT_OUTPUT_STYLE: stream-without-prefixes
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
jest_ew:
|
|
||||||
name: Jest (Element Web)
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
matrix:
|
|
||||||
# Run multiple instances in parallel to speed up the tests
|
|
||||||
runner: [1, 2]
|
|
||||||
steps:
|
|
||||||
- name: Checkout code
|
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
repository: ${{ inputs.matrix-js-sdk-sha && 'element-hq/element-web' || github.repository }}
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- name: pnpm cache
|
|
||||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
node-version: "lts/*"
|
|
||||||
cache: "pnpm"
|
|
||||||
|
|
||||||
- name: Install Deps
|
|
||||||
run: "./scripts/layered.sh"
|
|
||||||
env:
|
|
||||||
JS_SDK_GITHUB_BASE_REF: ${{ inputs.matrix-js-sdk-sha }}
|
|
||||||
|
|
||||||
- name: Jest Cache
|
|
||||||
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5
|
|
||||||
with:
|
|
||||||
path: /tmp/jest_cache
|
|
||||||
key: ${{ hashFiles('**/pnpm-lock.yaml') }}
|
|
||||||
|
|
||||||
- name: Get number of CPU cores
|
|
||||||
id: cpu-cores
|
|
||||||
uses: SimenB/github-actions-cpu-cores@97330871fe1b7d3529392ea000e3d2c4b357e403 # v3
|
|
||||||
|
|
||||||
- name: Run tests
|
|
||||||
working-directory: apps/web
|
|
||||||
run: |
|
|
||||||
pnpm test \
|
|
||||||
--coverage=$ENABLE_COVERAGE \
|
|
||||||
--ci \
|
|
||||||
--max-workers $MAX_WORKERS \
|
|
||||||
--shard "$SHARD" \
|
|
||||||
--cacheDirectory /tmp/jest_cache
|
|
||||||
env:
|
|
||||||
JEST_SONAR_UNIQUE_OUTPUT_NAME: true
|
|
||||||
|
|
||||||
# tell jest to use coloured output
|
|
||||||
FORCE_COLOR: true
|
|
||||||
MAX_WORKERS: ${{ steps.cpu-cores.outputs.count }}
|
|
||||||
SHARD: ${{ format('{0}/{1}', matrix.runner, strategy.job-total) }}
|
|
||||||
|
|
||||||
- name: Move coverage files into place
|
|
||||||
if: env.ENABLE_COVERAGE == 'true'
|
|
||||||
working-directory: apps/web
|
|
||||||
run: mv coverage/lcov.info coverage/$NODE_VERSION-${{ matrix.runner }}.lcov.info
|
|
||||||
env:
|
|
||||||
NODE_VERSION: ${{ steps.setupNode.outputs.node-version }}
|
|
||||||
|
|
||||||
- name: Upload Artifact
|
|
||||||
if: env.ENABLE_COVERAGE == 'true'
|
|
||||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
||||||
with:
|
|
||||||
name: coverage-jest-${{ matrix.runner }}
|
|
||||||
path: |
|
|
||||||
apps/web/coverage
|
|
||||||
!apps/web/coverage/lcov-report
|
|
||||||
|
|
||||||
complete:
|
|
||||||
name: jest-tests
|
|
||||||
needs: [jest_ew, vitest]
|
|
||||||
if: always()
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
permissions:
|
|
||||||
statuses: write
|
|
||||||
steps:
|
|
||||||
- if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')
|
|
||||||
run: exit 1
|
|
||||||
|
|
||||||
- name: Skip SonarCloud in merge queue
|
|
||||||
if: github.event_name == 'merge_group' || inputs.disable_coverage == 'true'
|
|
||||||
uses: guibranco/github-status-action-v2@9bfa8773cdbdc6c185747fd43cd7faa9d7c32f09
|
|
||||||
with:
|
|
||||||
authToken: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
state: success
|
|
||||||
description: SonarCloud skipped
|
|
||||||
context: SonarCloud Code Analysis
|
|
||||||
sha: ${{ github.sha }}
|
|
||||||
target_url: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}
|
|
||||||
|
|
||||||
vitest:
|
|
||||||
name: Vitest
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
path:
|
|
||||||
- apps/desktop
|
|
||||||
- packages/shared-components
|
|
||||||
- packages/module-api
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- name: Checkout code
|
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
repository: ${{ inputs.matrix-js-sdk-sha && 'element-hq/element-web' || github.repository }}
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- name: pnpm cache
|
|
||||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
node-version: "lts/*"
|
|
||||||
cache: "pnpm"
|
|
||||||
|
|
||||||
- name: Install Deps
|
|
||||||
run: "pnpm install"
|
|
||||||
|
|
||||||
- name: Cache storybook & vitest
|
|
||||||
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5
|
|
||||||
with:
|
|
||||||
path: |
|
|
||||||
${{ matrix.path }}/node_modules/.cache
|
|
||||||
${{ matrix.path }}/node_modules/.vite/vitest
|
|
||||||
key: ${{ matrix.path }}-${{ hashFiles('pnpm-lock.yaml') }}
|
|
||||||
|
|
||||||
- name: Setup playwright
|
|
||||||
uses: ./.github/actions/setup-playwright
|
|
||||||
if: matrix.path == 'packages/shared-components'
|
|
||||||
with:
|
|
||||||
write-cache: ${{ github.event_name != 'merge_group' }}
|
|
||||||
|
|
||||||
- name: Run tests
|
|
||||||
working-directory: ${{ matrix.path }}
|
|
||||||
run: pnpm test:unit --coverage=$ENABLE_COVERAGE
|
|
||||||
|
|
||||||
# Dump the disk usage on failure, because this job seems to fail with disk fills sometimes
|
|
||||||
- name: df
|
|
||||||
run: df -h && df -i
|
|
||||||
if: ${{ failure() }}
|
|
||||||
|
|
||||||
- name: Calculate artifact name
|
|
||||||
if: env.ENABLE_COVERAGE == 'true'
|
|
||||||
id: artifact
|
|
||||||
run: |
|
|
||||||
NAME=$(basename "$MATRIX_PATH")
|
|
||||||
echo "name=$NAME" >> $GITHUB_OUTPUT
|
|
||||||
env:
|
|
||||||
MATRIX_PATH: ${{ matrix.path }}
|
|
||||||
|
|
||||||
- name: Upload Artifact
|
|
||||||
if: env.ENABLE_COVERAGE == 'true'
|
|
||||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
||||||
with:
|
|
||||||
name: coverage-${{ steps.artifact.outputs.name }}
|
|
||||||
path: |
|
|
||||||
${{ matrix.path }}/coverage
|
|
||||||
!${{ matrix.path }}/coverage/lcov-report
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
name: Move issued assigned to specific team members to their boards
|
|
||||||
|
|
||||||
on:
|
|
||||||
issues:
|
|
||||||
types: [assigned]
|
|
||||||
|
|
||||||
permissions: {} # We use ELEMENT_BOT_TOKEN instead
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
web-app-team:
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: |
|
|
||||||
contains(github.event.issue.assignees.*.login, 't3chguy') ||
|
|
||||||
contains(github.event.issue.assignees.*.login, 'florianduros') ||
|
|
||||||
contains(github.event.issue.assignees.*.login, 'dbkr') ||
|
|
||||||
contains(github.event.issue.assignees.*.login, 'MidhunSureshR')
|
|
||||||
steps:
|
|
||||||
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: https://github.com/orgs/element-hq/projects/67
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
name: Move new issues into Issue triage board
|
|
||||||
|
|
||||||
on:
|
|
||||||
issues:
|
|
||||||
types: [opened]
|
|
||||||
|
|
||||||
permissions: {} # We use ELEMENT_BOT_TOKEN instead
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
automate-project-columns:
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: https://github.com/orgs/element-hq/projects/120
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
@@ -1,178 +0,0 @@
|
|||||||
name: Move labelled issues to correct projects
|
|
||||||
|
|
||||||
on:
|
|
||||||
issues:
|
|
||||||
types: [labeled]
|
|
||||||
workflow_call:
|
|
||||||
secrets:
|
|
||||||
ELEMENT_BOT_TOKEN:
|
|
||||||
required: true
|
|
||||||
|
|
||||||
permissions: {} # We use ELEMENT_BOT_TOKEN instead
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
apply_Z-Labs_label:
|
|
||||||
name: Add Z-Labs label for features behind labs flags
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Maths') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Location-Sharing') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'Z-IA') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Jump-To-Date ') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Themes-Custom') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-E2EE-Dehydration') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Tags') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Video-Rooms') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Message-Starring') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Rich-Text-Editor') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Element-Call')
|
|
||||||
steps:
|
|
||||||
- uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
|
|
||||||
with:
|
|
||||||
script: |
|
|
||||||
github.rest.issues.addLabels({
|
|
||||||
issue_number: context.issue.number,
|
|
||||||
owner: context.repo.owner,
|
|
||||||
repo: context.repo.repo,
|
|
||||||
labels: ['Z-Labs']
|
|
||||||
})
|
|
||||||
|
|
||||||
apply_Help-Wanted_label:
|
|
||||||
name: Add "Help Wanted" label to all "good first issue" and Hacktoberfest
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'good first issue') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'Hacktoberfest')
|
|
||||||
steps:
|
|
||||||
- uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
|
|
||||||
with:
|
|
||||||
script: |
|
|
||||||
github.rest.issues.addLabels({
|
|
||||||
issue_number: context.issue.number,
|
|
||||||
owner: context.repo.owner,
|
|
||||||
repo: context.repo.repo,
|
|
||||||
labels: ['Help Wanted']
|
|
||||||
})
|
|
||||||
|
|
||||||
move_needs_info_issues:
|
|
||||||
name: X-Needs-Info issues to Need info column on triage board
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'X-Needs-Info')
|
|
||||||
steps:
|
|
||||||
- id: add_to_project
|
|
||||||
uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: ${{ env.PROJECT_URL }}
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
|
|
||||||
- id: set_fields
|
|
||||||
uses: titoportas/update-project-fields@421a54430b3cdc9eefd8f14f9ce0142ab7678751 # v0.1.0
|
|
||||||
with:
|
|
||||||
project-url: ${{ env.PROJECT_URL }}
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
item-id: ${{ steps.add_to_project.outputs.itemId }} # Use the item-id output of the previous step
|
|
||||||
field-keys: Status
|
|
||||||
field-values: "Needs info"
|
|
||||||
env:
|
|
||||||
PROJECT_URL: https://github.com/orgs/element-hq/projects/120
|
|
||||||
|
|
||||||
move_flakey_test_issues:
|
|
||||||
name: Z-Flaky-Test issues to Sized for maintainer column on triage board
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'Z-Flaky-Test')
|
|
||||||
steps:
|
|
||||||
- id: add_to_project
|
|
||||||
uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: ${{ env.PROJECT_URL }}
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
|
|
||||||
- id: set_fields
|
|
||||||
uses: titoportas/update-project-fields@421a54430b3cdc9eefd8f14f9ce0142ab7678751 # v0.1.0
|
|
||||||
with:
|
|
||||||
project-url: ${{ env.PROJECT_URL }}
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
item-id: ${{ steps.add_to_project.outputs.itemId }} # Use the item-id output of the previous step
|
|
||||||
field-keys: Status
|
|
||||||
field-values: "Sized for maintainer"
|
|
||||||
env:
|
|
||||||
PROJECT_URL: https://github.com/orgs/element-hq/projects/120
|
|
||||||
|
|
||||||
add_priority_design_issues_to_project:
|
|
||||||
name: P1 X-Needs-Design to Design project board
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'X-Needs-Design') &&
|
|
||||||
(contains(github.event.issue.labels.*.name, 'S-Critical') &&
|
|
||||||
(contains(github.event.issue.labels.*.name, 'O-Frequent') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'O-Occasional')) ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'S-Major') &&
|
|
||||||
contains(github.event.issue.labels.*.name, 'O-Frequent') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A11y'))
|
|
||||||
steps:
|
|
||||||
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: https://github.com/orgs/element-hq/projects/18
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
|
|
||||||
add_product_issues:
|
|
||||||
name: X-Needs-Product to product project board
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'X-Needs-Product')
|
|
||||||
steps:
|
|
||||||
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: https://github.com/orgs/element-hq/projects/28
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
|
|
||||||
Search_issues_to_board:
|
|
||||||
name: Search issues to project board
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-New-Search-Experience')
|
|
||||||
steps:
|
|
||||||
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: https://github.com/orgs/element-hq/projects/48
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
|
|
||||||
voip:
|
|
||||||
name: Add labelled issues to VoIP project board
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'Team: VoIP')
|
|
||||||
steps:
|
|
||||||
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: https://github.com/orgs/element-hq/projects/41
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
|
|
||||||
crypto:
|
|
||||||
name: Add labelled issues to Crypto project
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'Team: Crypto')
|
|
||||||
steps:
|
|
||||||
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: https://github.com/orgs/element-hq/projects/76
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
|
|
||||||
tech_debt:
|
|
||||||
name: Add labelled issues to tech debt project
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Developer-Experience') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Documentation') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Packaging') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Technical-Debt') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Testing') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'Z-Flaky-Test')
|
|
||||||
steps:
|
|
||||||
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
|
|
||||||
with:
|
|
||||||
project-url: https://github.com/orgs/element-hq/projects/101
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
@@ -1,140 +0,0 @@
|
|||||||
name: Move pull requests asking for review to the relevant project
|
|
||||||
on:
|
|
||||||
pull_request_target:
|
|
||||||
types: [review_requested]
|
|
||||||
|
|
||||||
permissions: {} # Uses ELEMENT_BOT_TOKEN instead
|
|
||||||
jobs:
|
|
||||||
add_design_pr_to_project:
|
|
||||||
name: Move PRs asking for design review to the design board
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: octokit/graphql-action@ddde8ebb2493e79f390e6449c725c21663a67505 # v3.0.2
|
|
||||||
id: find_team_members
|
|
||||||
with:
|
|
||||||
headers: '{"GraphQL-Features": "projects_next_graphql"}'
|
|
||||||
query: |
|
|
||||||
query find_team_members($team: String!) {
|
|
||||||
organization(login: "element-hq") {
|
|
||||||
team(slug: $team) {
|
|
||||||
members {
|
|
||||||
nodes {
|
|
||||||
login
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
team: ${{ env.TEAM }}
|
|
||||||
env:
|
|
||||||
TEAM: "design"
|
|
||||||
GITHUB_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
- id: any_matching_reviewers
|
|
||||||
run: |
|
|
||||||
# Fetch requested reviewers, and people who are on the team
|
|
||||||
echo '${{ tojson(fromjson(steps.find_team_members.outputs.data).organization.team.members.nodes[*].login) }}' | tee /tmp/team_members.json
|
|
||||||
echo '${{ tojson(github.event.pull_request.requested_reviewers[*].login) }}' | tee /tmp/reviewers.json
|
|
||||||
jq --raw-output .[] < /tmp/team_members.json | sort | tee /tmp/team_members.txt
|
|
||||||
jq --raw-output .[] < /tmp/reviewers.json | sort | tee /tmp/reviewers.txt
|
|
||||||
|
|
||||||
# Fetch requested team reviewers, and the name of the team
|
|
||||||
echo '${{ tojson(github.event.pull_request.requested_teams[*].slug) }}' | tee /tmp/team_reviewers.json
|
|
||||||
jq --raw-output .[] < /tmp/team_reviewers.json | sort | tee /tmp/team_reviewers.txt
|
|
||||||
echo '${{ env.TEAM }}' | tee /tmp/team.txt
|
|
||||||
|
|
||||||
# If either a reviewer matches a team member, or a team matches our team, say "true"
|
|
||||||
if [ $(join /tmp/team_members.txt /tmp/reviewers.txt | wc -l) != 0 ]; then
|
|
||||||
echo "match=true" >> $GITHUB_OUTPUT
|
|
||||||
elif [ $(join /tmp/team.txt /tmp/team_reviewers.txt | wc -l) != 0 ]; then
|
|
||||||
echo "match=true" >> $GITHUB_OUTPUT
|
|
||||||
else
|
|
||||||
echo "match=false" >> $GITHUB_OUTPUT
|
|
||||||
fi
|
|
||||||
env:
|
|
||||||
TEAM: "design"
|
|
||||||
- uses: octokit/graphql-action@ddde8ebb2493e79f390e6449c725c21663a67505 # v3.0.2
|
|
||||||
id: add_to_project
|
|
||||||
if: steps.any_matching_reviewers.outputs.match == 'true'
|
|
||||||
with:
|
|
||||||
headers: '{"GraphQL-Features": "projects_next_graphql"}'
|
|
||||||
query: |
|
|
||||||
mutation add_to_project($projectid:ID!, $contentid:ID!) {
|
|
||||||
addProjectV2ItemById(input: {projectId: $projectid contentId: $contentid}) {
|
|
||||||
item {
|
|
||||||
id
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
projectid: ${{ env.PROJECT_ID }}
|
|
||||||
contentid: ${{ github.event.pull_request.node_id }}
|
|
||||||
env:
|
|
||||||
PROJECT_ID: "PVT_kwDOAM0swc0sUA"
|
|
||||||
TEAM: "design"
|
|
||||||
GITHUB_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
|
|
||||||
add_product_pr_to_project:
|
|
||||||
name: Move PRs asking for design review to the design board
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: octokit/graphql-action@ddde8ebb2493e79f390e6449c725c21663a67505 # v3.0.2
|
|
||||||
id: find_team_members
|
|
||||||
with:
|
|
||||||
headers: '{"GraphQL-Features": "projects_next_graphql"}'
|
|
||||||
query: |
|
|
||||||
query find_team_members($team: String!) {
|
|
||||||
organization(login: "element-hq") {
|
|
||||||
team(slug: $team) {
|
|
||||||
members {
|
|
||||||
nodes {
|
|
||||||
login
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
team: ${{ env.TEAM }}
|
|
||||||
env:
|
|
||||||
TEAM: "product"
|
|
||||||
GITHUB_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
- id: any_matching_reviewers
|
|
||||||
run: |
|
|
||||||
# Fetch requested reviewers, and people who are on the team
|
|
||||||
echo '${{ tojson(fromjson(steps.find_team_members.outputs.data).organization.team.members.nodes[*].login) }}' | tee /tmp/team_members.json
|
|
||||||
echo '${{ tojson(github.event.pull_request.requested_reviewers[*].login) }}' | tee /tmp/reviewers.json
|
|
||||||
jq --raw-output .[] < /tmp/team_members.json | sort | tee /tmp/team_members.txt
|
|
||||||
jq --raw-output .[] < /tmp/reviewers.json | sort | tee /tmp/reviewers.txt
|
|
||||||
|
|
||||||
# Fetch requested team reviewers, and the name of the team
|
|
||||||
echo '${{ tojson(github.event.pull_request.requested_teams[*].slug) }}' | tee /tmp/team_reviewers.json
|
|
||||||
jq --raw-output .[] < /tmp/team_reviewers.json | sort | tee /tmp/team_reviewers.txt
|
|
||||||
echo '${{ env.TEAM }}' | tee /tmp/team.txt
|
|
||||||
|
|
||||||
# If either a reviewer matches a team member, or a team matches our team, say "true"
|
|
||||||
if [ $(join /tmp/team_members.txt /tmp/reviewers.txt | wc -l) != 0 ]; then
|
|
||||||
echo "match=true" >> $GITHUB_OUTPUT
|
|
||||||
elif [ $(join /tmp/team.txt /tmp/team_reviewers.txt | wc -l) != 0 ]; then
|
|
||||||
echo "match=true" >> $GITHUB_OUTPUT
|
|
||||||
else
|
|
||||||
echo "match=false" >> $GITHUB_OUTPUT
|
|
||||||
fi
|
|
||||||
env:
|
|
||||||
TEAM: "product"
|
|
||||||
- uses: octokit/graphql-action@ddde8ebb2493e79f390e6449c725c21663a67505 # v3.0.2
|
|
||||||
id: add_to_project
|
|
||||||
if: steps.any_matching_reviewers.outputs.match == 'true'
|
|
||||||
with:
|
|
||||||
headers: '{"GraphQL-Features": "projects_next_graphql"}'
|
|
||||||
query: |
|
|
||||||
mutation add_to_project($projectid:ID!, $contentid:ID!) {
|
|
||||||
addProjectV2ItemById(input: {projectId: $projectid contentId: $contentid}) {
|
|
||||||
item {
|
|
||||||
id
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
projectid: ${{ env.PROJECT_ID }}
|
|
||||||
contentid: ${{ github.event.pull_request.node_id }}
|
|
||||||
env:
|
|
||||||
PROJECT_ID: "PVT_kwDOAM0swc4AAg6N"
|
|
||||||
TEAM: "product"
|
|
||||||
GITHUB_TOKEN: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
name: Close stale issues & PRs
|
|
||||||
on:
|
|
||||||
workflow_dispatch: {}
|
|
||||||
schedule:
|
|
||||||
- cron: "30 1 * * *"
|
|
||||||
permissions: {}
|
|
||||||
jobs:
|
|
||||||
close:
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
permissions:
|
|
||||||
actions: write
|
|
||||||
issues: write
|
|
||||||
pull-requests: write
|
|
||||||
steps:
|
|
||||||
- uses: actions/stale@b5d41d4e1d5dceea10e7104786b73624c18a190f # v10
|
|
||||||
with:
|
|
||||||
operations-per-run: 100
|
|
||||||
|
|
||||||
# Flaky test issue closing
|
|
||||||
any-of-issue-labels: "Z-Flaky-Test-Chrome,Z-Flaky-Test-Firefox,Z-Flaky-Test-Webkit"
|
|
||||||
days-before-issue-stale: 14
|
|
||||||
days-before-issue-close: 0
|
|
||||||
close-issue-message: "This flaky test issue has not been updated in 14 days. It is being closed as presumed resolved."
|
|
||||||
exempt-issue-labels: "Z-Flaky-Test-Disabled"
|
|
||||||
|
|
||||||
# Stale PR closing
|
|
||||||
days-before-pr-stale: 180
|
|
||||||
days-before-pr-close: 0
|
|
||||||
close-pr-message: "This PR has been automatically closed because it has been stale for 180 days. If you wish to continue working on this PR, please ping a maintainer to reopen it."
|
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
name: Move unlabelled from needs info columns to triaged
|
|
||||||
|
|
||||||
on:
|
|
||||||
issues:
|
|
||||||
types: [unlabeled]
|
|
||||||
permissions: {}
|
|
||||||
jobs:
|
|
||||||
move_no_longer_needs_info_issues:
|
|
||||||
name: Move no longer X-Needs-Info issues to Triaged
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
!contains(github.event.issue.labels.*.name, 'X-Needs-Info')
|
|
||||||
steps:
|
|
||||||
- id: set_fields
|
|
||||||
uses: nipe0324/update-project-v2-item-field@c4af58452d1c5a788c1ea4f20e073fa722ec4a6b #v2.0.2
|
|
||||||
with:
|
|
||||||
project-url: ${{ env.PROJECT_URL }}
|
|
||||||
github-token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
skip-update-script: |
|
|
||||||
const isIssue = item.type === 'ISSUE'
|
|
||||||
const status = item.fieldValues['Status']
|
|
||||||
return !isIssue || status !== 'Needs info'
|
|
||||||
field-name: Status
|
|
||||||
field-value: "Triaged"
|
|
||||||
env:
|
|
||||||
PROJECT_URL: https://github.com/orgs/element-hq/projects/120
|
|
||||||
|
|
||||||
remove_Z-Labs_label:
|
|
||||||
name: Remove Z-Labs label when features behind labs flags are removed
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
if: >
|
|
||||||
!(contains(github.event.issue.labels.*.name, 'A-Maths') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Message-Pinning') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Location-Sharing') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'Z-IA') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Jump-To-Date') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Themes-Custom') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-E2EE-Dehydration') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Tags') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Video-Rooms') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Message-Starring') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Rich-Text-Editor') ||
|
|
||||||
contains(github.event.issue.labels.*.name, 'A-Element-Call')) &&
|
|
||||||
contains(github.event.issue.labels.*.name, 'Z-Labs')
|
|
||||||
steps:
|
|
||||||
- uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
|
|
||||||
with:
|
|
||||||
script: |
|
|
||||||
github.rest.issues.removeLabel({
|
|
||||||
issue_number: context.issue.number,
|
|
||||||
owner: context.repo.owner,
|
|
||||||
repo: context.repo.repo,
|
|
||||||
name: ['Z-Labs']
|
|
||||||
})
|
|
||||||
@@ -1,37 +0,0 @@
|
|||||||
# Re-fetches the Jitsi SDK and opens a PR to update it if it's different from what's in the repository
|
|
||||||
name: Update Jitsi
|
|
||||||
on:
|
|
||||||
workflow_dispatch: {}
|
|
||||||
schedule:
|
|
||||||
- cron: "0 3 * * 0" # 3am every Sunday
|
|
||||||
permissions: {} # We use ELEMENT_BOT_TOKEN instead
|
|
||||||
jobs:
|
|
||||||
update:
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
|
|
||||||
with:
|
|
||||||
persist-credentials: false
|
|
||||||
|
|
||||||
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
|
|
||||||
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
|
|
||||||
with:
|
|
||||||
cache: "pnpm"
|
|
||||||
node-version: "lts/*"
|
|
||||||
|
|
||||||
- name: Install Deps
|
|
||||||
run: "pnpm install --frozen-lockfile"
|
|
||||||
|
|
||||||
- name: Fetch Jitsi
|
|
||||||
working-directory: apps/web
|
|
||||||
run: "pnpm vendor:jitsi"
|
|
||||||
|
|
||||||
- name: Create Pull Request
|
|
||||||
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8
|
|
||||||
with:
|
|
||||||
token: ${{ secrets.ELEMENT_BOT_TOKEN }}
|
|
||||||
branch: actions/jitsi-update
|
|
||||||
delete-branch: true
|
|
||||||
title: Jitsi Update
|
|
||||||
labels: |
|
|
||||||
T-Task
|
|
||||||
@@ -1,119 +0,0 @@
|
|||||||
name: Update release topics
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
expected_status:
|
|
||||||
description: What type of release is the next expected release
|
|
||||||
required: true
|
|
||||||
default: RC
|
|
||||||
type: choice
|
|
||||||
options:
|
|
||||||
- RC
|
|
||||||
- Release
|
|
||||||
expected_date:
|
|
||||||
description: Expected release date e.g. July 11th
|
|
||||||
required: true
|
|
||||||
type: string
|
|
||||||
concurrency: ${{ github.workflow }}
|
|
||||||
permissions: {} # No permissions required
|
|
||||||
jobs:
|
|
||||||
bot:
|
|
||||||
name: Release topic update
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
environment: Matrix
|
|
||||||
steps:
|
|
||||||
- uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
|
|
||||||
env:
|
|
||||||
HS_URL: ${{ secrets.BETABOT_HS_URL }}
|
|
||||||
LOBBY_ROOM_ID: ${{ secrets.ROOM_ID }}
|
|
||||||
PUBLIC_DISCUSSION_ROOM_ID: "!xUW4PpAe1CmThA3r2wI8IrgwwsK006-zqWdJCljpd10"
|
|
||||||
ANNOUNCEMENT_ROOM_ID: "!ars5ndgI6IIYZXECiJ-u8YljHNzShJn3nHdB-3rYI2M"
|
|
||||||
TOKEN: ${{ secrets.BETABOT_ACCESS_TOKEN }}
|
|
||||||
RELEASE_STATUS: "Release status: ${{ inputs.expected_status }} expected ${{ inputs.expected_date }}"
|
|
||||||
with:
|
|
||||||
script: |
|
|
||||||
const { HS_URL, TOKEN, RELEASE_STATUS, LOBBY_ROOM_ID, PUBLIC_DISCUSSION_ROOM_ID, ANNOUNCEMENT_ROOM_ID } = process.env;
|
|
||||||
|
|
||||||
const repo = context.repo;
|
|
||||||
const { data } = await github.rest.repos.getLatestRelease({
|
|
||||||
owner: repo.owner,
|
|
||||||
repo: repo.repo,
|
|
||||||
});
|
|
||||||
console.log("Found latest version: " + data.tag_name);
|
|
||||||
|
|
||||||
const releaseTopic = `Stable: ${data.tag_name} | ${RELEASE_STATUS}`;
|
|
||||||
console.log("Release topic: " + releaseTopic);
|
|
||||||
|
|
||||||
const regex = /Stable: v(.+) \| Release status: (\w+) expected (\w+ \d+\w\w)/gm;
|
|
||||||
|
|
||||||
async function updateReleaseInTopic(roomId) {
|
|
||||||
const apiUrl = `${HS_URL}/_matrix/client/v3/rooms/${roomId}/state/m.room.topic/`;
|
|
||||||
const headers = {
|
|
||||||
"Content-Type": "application/json",
|
|
||||||
"Authorization": `Bearer ${TOKEN}`,
|
|
||||||
};
|
|
||||||
await fetch(`${HS_URL}/_matrix/client/v3/rooms/${roomId}/join`, {
|
|
||||||
method: "POST",
|
|
||||||
headers,
|
|
||||||
body: "{}",
|
|
||||||
});
|
|
||||||
|
|
||||||
let res = await fetch(apiUrl, {
|
|
||||||
method: "GET",
|
|
||||||
headers,
|
|
||||||
});
|
|
||||||
|
|
||||||
if (!res.ok) {
|
|
||||||
console.log(roomId, "failed to fetch", await res.text());
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
const data = await res.json();
|
|
||||||
console.log(roomId, "got event", data);
|
|
||||||
|
|
||||||
if (!regex.test(data.topic)) {
|
|
||||||
core.setFailed("Topic format is incorrect for room " + roomId);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
const topic = data.topic.replace(regex, releaseTopic);
|
|
||||||
if (topic === data.topic) {
|
|
||||||
console.log(roomId, "nothing to do");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
if (data["org.matrix.msc3765.topic"]) {
|
|
||||||
data["org.matrix.msc3765.topic"]?.["m.text"].forEach(d => {
|
|
||||||
d.body = d.body.replace(regex, releaseTopic);
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (data["m.topic"]) {
|
|
||||||
data["m.topic"]?.["m.text"].forEach(d => {
|
|
||||||
d.body = d.body.replace(regex, releaseTopic);
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
res = await fetch(apiUrl, {
|
|
||||||
method: "PUT",
|
|
||||||
body: JSON.stringify({
|
|
||||||
...data,
|
|
||||||
topic,
|
|
||||||
}),
|
|
||||||
headers,
|
|
||||||
});
|
|
||||||
|
|
||||||
if (res.ok) {
|
|
||||||
const resJson = res.json();
|
|
||||||
if (resJson.errcode) {
|
|
||||||
core.setFailed(`Error updating ${roomId}: ${resJson.error}`);
|
|
||||||
} else {
|
|
||||||
console.log(roomId, "topic updated:", topic);
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
const errText = await res.text();
|
|
||||||
core.setFailed(`Error updating ${roomId}: ${errText}`);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
await updateReleaseInTopic(LOBBY_ROOM_ID);
|
|
||||||
await updateReleaseInTopic(PUBLIC_DISCUSSION_ROOM_ID);
|
|
||||||
await updateReleaseInTopic(ANNOUNCEMENT_ROOM_ID);
|
|
||||||
Reference in New Issue
Block a user