-
Notifications
You must be signed in to change notification settings - Fork 5
160 lines (138 loc) · 6.8 KB
/
Copy pathsync-ii-spec.yml
File metadata and controls
160 lines (138 loc) · 6.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
name: Sync II spec
on:
schedule:
- cron: '0 9 * * 2' # Weekly on Tuesday (II releases are typically Monday/Tuesday)
workflow_dispatch:
jobs:
sync:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
fetch-depth: 0
- name: Create GitHub App Token
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
id: app-token
with:
client-id: ${{ vars.PR_AUTOMATION_BOT_PUBLIC_CLIENT_ID }}
private-key: ${{ secrets.PR_AUTOMATION_BOT_PUBLIC_PRIVATE_KEY }}
- name: Initialize internetidentity submodule at current pin
run: |
git config --global url."https://github.com/".insteadOf "git@github.com:"
git submodule update --init --depth 1 .sources/internetidentity
- name: Get current pinned hash
id: current
run: |
HASH=$(git -C .sources/internetidentity rev-parse HEAD)
echo "hash=$HASH" >> $GITHUB_OUTPUT
echo "short=$(git -C .sources/internetidentity rev-parse --short HEAD)" >> $GITHUB_OUTPUT
- name: Fetch latest release tag and resolve hash
id: latest
run: |
git -C .sources/internetidentity fetch --tags --depth 100 origin
TAG=$(git -C .sources/internetidentity tag --sort=-version:refname \
| grep '^release-[0-9][0-9][0-9][0-9]-' | head -1)
echo "Latest release tag: $TAG"
HASH=$(git -C .sources/internetidentity rev-parse "$TAG")
SHORT=$(git -C .sources/internetidentity rev-parse --short "$TAG")
echo "tag=$TAG" >> $GITHUB_OUTPUT
echo "hash=$HASH" >> $GITHUB_OUTPUT
echo "short=$SHORT" >> $GITHUB_OUTPUT
- name: Check if relevant files changed
id: check
run: |
CURRENT="${{ steps.current.outputs.hash }}"
LATEST="${{ steps.latest.outputs.hash }}"
BRANCH="infra/sync-ii-spec-${{ steps.latest.outputs.tag }}"
if [ "$CURRENT" = "$LATEST" ]; then
echo "Already at latest release ${{ steps.latest.outputs.tag }}. No update needed."
echo "needed=false" >> $GITHUB_OUTPUT
exit 0
fi
if git ls-remote --exit-code origin "refs/heads/${BRANCH}" > /dev/null 2>&1; then
echo "Branch $BRANCH already exists — PR likely open, skipping."
echo "needed=false" >> $GITHUB_OUTPUT
exit 0
fi
# Only proceed if the spec files themselves changed
CHANGED=$(git -C .sources/internetidentity diff --name-only "${CURRENT}..${LATEST}" -- \
docs/ii-spec.mdx \
docs/vc-spec.md \
src/internet_identity/internet_identity.did)
if [ -z "$CHANGED" ]; then
echo "No changes to ii-spec.mdx, vc-spec.md, or internet_identity.did. Skipping."
echo "needed=false" >> $GITHUB_OUTPUT
else
echo "Spec files changed:"
echo "$CHANGED"
echo "needed=true" >> $GITHUB_OUTPUT
echo "changed_files<<EOF" >> $GITHUB_OUTPUT
echo "$CHANGED" >> $GITHUB_OUTPUT
echo "EOF" >> $GITHUB_OUTPUT
fi
- name: Bump submodule to latest main
if: steps.check.outputs.needed == 'true'
run: git -C .sources/internetidentity checkout ${{ steps.latest.outputs.hash }}
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
if: steps.check.outputs.needed == 'true'
with:
node-version: 22
cache: npm
- name: Install dependencies
if: steps.check.outputs.needed == 'true'
run: npm ci
- name: Initialize examples submodule (required for build)
if: steps.check.outputs.needed == 'true'
run: git submodule update --init --depth 1 .sources/examples
- name: Run II spec sync
if: steps.check.outputs.needed == 'true'
run: npm run sync:ii-spec
- name: Build check
if: steps.check.outputs.needed == 'true'
run: npm run build
- name: Update VERSIONS
if: steps.check.outputs.needed == 'true'
run: |
sed -i "s|^internetidentity.*|internetidentity ${{ steps.latest.outputs.tag }} ${{ steps.latest.outputs.short }}|" .sources/VERSIONS
- name: Create PR
if: steps.check.outputs.needed == 'true'
run: |
git config user.name "pr-automation-bot-public[bot]"
git config user.email "pr-automation-bot-public[bot]@users.noreply.github.com"
BRANCH="infra/sync-ii-spec-${{ steps.latest.outputs.tag }}"
git checkout -b "$BRANCH"
git add .sources/internetidentity docs/references/internet-identity-spec.md docs/references/verifiable-credentials-spec.md public/references/internet-identity.did .sources/VERSIONS
git commit -m "chore: sync II spec to dfinity/internet-identity ${{ steps.latest.outputs.tag }}"
git push -u origin "$BRANCH"
CHANGED="${{ steps.check.outputs.changed_files }}"
{
echo "## Summary"
echo ""
echo "Automated sync of the Internet Identity specification from \`dfinity/internet-identity\`."
echo ""
echo "**Release:** \`${{ steps.latest.outputs.tag }}\` (pinned from \`${{ steps.current.outputs.short }}\` → \`${{ steps.latest.outputs.short }}\`)"
echo ""
echo "**Changed upstream files:**"
while IFS= read -r f; do
[ -n "$f" ] && echo "- \`$f\`"
done <<< "$CHANGED"
echo ""
echo "- Ran \`npm run sync:ii-spec\` — regenerated \`docs/references/internet-identity-spec.md\` and \`docs/references/verifiable-credentials-spec.md\`"
echo "- Build passed ✓"
echo ""
echo "## Checklist"
echo ""
echo "- [ ] Review the diff to \`docs/references/internet-identity-spec.md\` for content changes"
echo "- [ ] Review the diff to \`docs/references/verifiable-credentials-spec.md\` for content changes"
echo "- [ ] Check for new absolute \`internetcomputer.org\` link patterns (script exits non-zero if any were missed)"
echo "- [ ] Verify any renamed or restructured sections are reflected correctly"
echo ""
echo "## Sync recommendation"
echo ""
echo "\`sync from dfinity/internet-identity — docs/ii-spec.mdx, docs/vc-spec.md, src/internet_identity/internet_identity.did\`"
} > /tmp/pr-body.md
gh pr create \
--title "chore: sync II spec to dfinity/internet-identity ${{ steps.latest.outputs.tag }}" \
--body-file /tmp/pr-body.md
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}